Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects the suspicious retrieval and immediate execution of Agentic AI configuration files (e.g., AGENTS.md, KNOWLEDGE.md) from remote sources using common command-line utilities. This pattern is indicative of an adversary injecting malicious agent instructions or unauthorized configurations into an AI environment.
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
This rule detects potential phishing or HTML smuggling attempts by identifying a burst of anomalously large SVG file attachments delivered via email to multiple recipients, followed by a correlation with web browser process network activity from the same recipients shortly after the email delivery.
Detects the use of PowerShell or Windows Script Host to access files within common web browser cache directories combined with indicators of Base64 decoding and pixel data manipulation. This behavior is indicative of extracting malicious payloads hidden via steganography within browser-cached image files, a technique often used in phishing campaigns to evade detection.
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
Detects the presence of package.json or node_modules artifacts associated with a known typosquatting campaign targeting the 'sorted-btree' npm package. The rule identifies suspicious package names or dependencies by matching against a list of known malicious packages used in the campaign, or by detecting the co-occurrence of the malicious 'indexed-btree' package alongside the legitimate 'sorted-btree' package.
Detects the execution of command-line interpreters (cmd, powershell, mshta, etc.) directly spawned by explorer.exe. This activity is indicative of the 'ClickFix' or 'ConsentFix' attack chain, where a victim is coerced into pasting malicious commands into the Windows Run dialog (Win+R) after interacting with a fraudulent CAPTCHA or verification page in their browser. The rule filters out standard installer-related activity to reduce false positives.
Detects instances where PowerShell or pwsh processes are initiated directly by explorer.exe containing command-line arguments indicative of obfuscated or hidden execution, often used in ClickFix-style social engineering attacks where victims are coerced into pasting malicious commands into the Windows Run dialog.
Detects registry value modifications to the Windows Explorer RunMRU key where the data contains indicators of obfuscated PowerShell commands. This pattern is commonly associated with the 'ClickFix' social-engineering campaign, where users are prompted to copy and paste a malicious PowerShell command into the Windows Run dialog.
Detects the abuse of Windows protocol handlers ('search-ms:') and WebDAV UNC paths ('@SSL\DavWWWRoot') launched from common web browsers or Windows shell processes. This technique, frequently observed in 'ClickFix' phishing campaigns, enables attackers to stage remote payloads like LNK, HTA, or scripts by leveraging native Windows functionality to resolve remote content as if it were a local resource, bypassing typical file download security controls.
Detects instances where a suspected malicious loader initiates process hollowing or APC injection by launching trusted Windows binaries (e.g., LockAppHost.exe, makecab.exe, Magnify.exe) in a suspended state. The rule identifies suspicious post-injection behavior such as unexpected network connections or child process creation originating from these typically benign binaries, which is characteristic of the DeepLoad/ClickFix attack chain.
Detects the execution of 'sqlcmd.exe' when spawned by web application pools (w3wp.exe) or general command shell (cmd.exe) processes that do not appear to be related to authorized database administration or IIS appcmd activity.
Detects the use of 'findstr' or PowerShell to query sensitive configuration files (such as web.config or applicationHost.config) for credential-related keywords like 'connectionString', 'AccountKey', or 'machineKey'. This behavior is indicative of an adversary attempting to harvest credentials or sensitive configuration data stored in cleartext on the filesystem.
Detects the Microsoft IIS worker process (w3wp.exe) spawning common command-line shells (cmd.exe or powershell.exe) and executing discovery-related commands. This is highly indicative of potential web shell activity where an adversary uses an existing web application vulnerability to gain remote code execution.
Detects the presence of known SHA256 hashes associated with the 'ccrtc' planter PowerShell scripts and C2 SDK JavaScript components. These files were identified as being dropped into 'C:\Windows\Temp' during the STAC4924 webshell intrusion campaign.
Detects the creation of an ASPX file within a member file upload directory, followed immediately by the execution of 'cmd.exe' by the 'w3wp.exe' web server process. This behavior is indicative of a web shell being uploaded and used to execute arbitrary commands on the server.
Detects reconnaissance activity on IIS servers where the worker process (w3wp.exe) spawns appcmd.exe or PowerShell to list websites, virtual directories, or application pools. This pattern is indicative of an attacker performing post-exploitation discovery after establishing a web shell.
Detects instances where a Microsoft IIS worker process (w3wp.exe) executes commands such as 'findstr', 'Get-Content', or 'Select-Xml' to scan configuration files (e.g., applicationHost.config, web.config) or source code files (e.g., App_Code/*.cs) for sensitive information like passwords, connection strings, or API keys. This behavior is indicative of credential harvesting by an attacker using a webshell or compromised IIS process.
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates a child process of sqlcmd.exe. This behavior is highly suspicious and often indicates a post-exploitation activity where an attacker, having established a webshell or similar foothold on a web server, is using harvested credentials to query backend SQL databases directly.
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates a child process of sqlcmd.exe. This behavior is highly suspicious and often indicates a post-exploitation activity where an attacker, having established a webshell or similar foothold on a web server, is using harvested credentials to query backend SQL databases directly.
Detects instances where an IIS worker process (w3wp.exe) spawns a command shell (cmd.exe) that executes a conditional file copy operation. This pattern is characteristic of an adversary creating a webshell by copying a payload to a filename that masquerades as a legitimate web application asset, such as a CSS bundle or validation script.
Page 58 of 1866

