Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects high-volume RDP X.224 connection requests originating from a single source within a short timeframe, which is a strong indicator of a brute force or password spraying attack targeting Remote Desktop Protocol services.
Detects outbound network traffic matching Stratum protocol JSON-RPC methods (mining.subscribe, mining.authorize, mining.submit) typically used by XMRig and other cryptomining software to communicate with a mining pool. The rule monitors for established TCP connections on non-standard ports, excluding common web ports 80 and 443.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule detects instances where the WMI Provider Host process (wmiprvse.exe) initiates a child process. While WMI is a legitimate administrative tool, it is frequently abused by attackers for lateral movement, remote code execution, and persistent event subscriptions. Monitoring for child processes spawned by wmiprvse.exe can highlight potentially malicious activity triggered via WMI.
Detects the deletion of volume shadow copies using standard Windows utilities vssadmin.exe or wmic.exe. This activity is a common indicator of ransomware or other destructive attacks attempting to inhibit system recovery.
Detects repeated file creation or modification events involving the specific file 'bot_log.txt' in directory paths containing '\Temp\' on endpoints where 'msedge_proxy.exe' is also running. This pattern is indicative of potential data staging or logging activities by an unauthorized proxy or tunnel process.
Matches known SHA-256 hashes for the BotHelper stager (WindowsUpdate.exe) and RAT (msedge_proxy.exe)
Detects potential command and control (C2) activity associated with the BotHelper malware. The rule correlates a process downloading files or DLL plugins from specific C2 URL paths ('/uploads/Files/' or '/uploads/Plugins/') with a subsequent report of task execution status ('task_run.php' or 'task_failed.php') originating from the same process within a 10-minute window.
Detects host-control and management tasks (e.g., shutdown, logoff, scheduled task modification) executed as child processes of the msedge_proxy.exe process. This behavior is indicative of the BotHelper malware implant managing infected endpoints.
Detects usage of Crowdstrike Real Time Response (RTR) to execute a "runscript" command.
This can be used by malicious actors with access to the Crowdstrike Dashboard to execute commands on remote managed hosts.
This can be used by malicious actors with access to the Crowdstrike Dashboard to execute commands on remote managed hosts.
Detects the execution of a .pif (Program Information File) process where the filename contains keywords suggestive of image files (e.g., 'image', 'photo', 'scan'). Adversaries often use this technique to trick users into executing malicious code by masquerading the file type.
Detects the DarkMe downloader chain involving staging via WebDAV UNC paths, extraction of password-protected archives using 7-Zip, and subsequent execution using rundll32.exe with the specific RunDllEntryPointW export, which is indicative of this malware's execution flow.
This rule detects network activity associated with the DarkMe RAT, specifically targeting outbound TCP connections or DNS resolutions involving known C2 domains by the rundll32.exe process. This activity is indicative of the malware's post-injection C2 registration and beaconing.
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
Detects ClickFix-style social engineering attacks where users are tricked into pasting malicious payloads into the Windows Run dialog. The rule monitors for common scripting interpreters (powershell.exe, cmd.exe, mshta.exe, rundll32.exe) spawned by explorer.exe or mstsc.exe with suspicious command-line patterns indicative of payload delivery, such as obfuscated strings, hidden windows, or short-URL downloads.
Detects instances where a signed executable, typically a security or trusted system binary, loads an unsigned DLL from a user-writable, non-default directory (e.g., Temp, AppData, ProgramData). The rule specifically targets common system or vendor library names, indicating potential DLL search-order hijacking used to execute malicious code within a trusted process context.
Detects suspicious network activity or credential exfiltration attempts occurring during package manager installation processes (npm, pip, yarn). The rule monitors for lifecycle scripts (e.g., preinstall, postinstall) spawning network utilities to external destinations or accessing common CI/CD secrets like AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN.
Detects execution of mshta.exe when initiated by common office or web browser applications, or when command arguments include external network references (URLs/UNC paths) or script protocols (vbscript/javascript), which are common patterns for LOLBAS-based initial access or exploitation.
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
Page 57 of 1870


