Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution or presence of AnyDesk.exe within directories containing 'UBP-Asset' that are outside of known, legitimate installation paths. This behavior often indicates an adversary attempting to use remote access software for persistent access or command and control, commonly disguised within unconventional directories.
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
Detects the execution of PowerShell with a bypass execution policy that performs a download or web request to save content to a file in the user's temp directory, followed by the immediate execution of that file. This pattern is characteristic of multi-stage malware droppers or fileless attack techniques attempting to stage and execute malicious scripts from temporary locations.
Detects the WAV-based loader staging technique: a RIFF/WAVE file carrying a high-entropy appended blob, or a companion DLL chain (rdCore.dll/WMPCL.dll/WPFLocalizeExtension.dll) referencing the hidden audio payload and the encrypted monitor.raw container used to unpack the final RAT
Detects instances where rundll32.exe is used to invoke shell32.dll with the SHCreateLocal function, or where a web browser process (msedge.exe, chrome.exe, or firefox.exe) is spawned by rundll32.exe to open an HTML file. This pattern is often indicative of malicious activity such as HTML smuggling or local file execution attacks where rundll32 is used as a proxy to open files via the browser.
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
Detects >=2 of the four NeedyMantis archive-extraction artifacts (encryptbase64.ps1, dnsapi.dll, ws2_32.dll, msvcrt140.dll) written by the same process within 60 seconds. Anchored to the known sideload staging directories (ProgramData/ProgramFiles subfolders used by the Poedit/curl/Vim/TightVNC/Office/Broadcom/Intel/NVIDIA-masquerading bundles) and excludes System32/SysWOW64, since ws2_32.dll and dnsapi.dll are legitimate system DLL names that would otherwise cause noise if matched by name alone anywhere on disk.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
Detects instances where a browser or agentic-browser process initiates a file download and subsequently executes that same file within a five-minute window, without the intervention of a user-driven process like explorer.exe. This pattern is indicative of automated 'agentic' browser activity, potentially signifying hijacked web instructions or malicious automated tool execution flows.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
Detects the suspicious retrieval and immediate execution of Agentic AI configuration files (e.g., AGENTS.md, KNOWLEDGE.md) from remote sources using common command-line utilities. This pattern is indicative of an adversary injecting malicious agent instructions or unauthorized configurations into an AI environment.
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
This rule detects potential phishing or HTML smuggling attempts by identifying a burst of anomalously large SVG file attachments delivered via email to multiple recipients, followed by a correlation with web browser process network activity from the same recipients shortly after the email delivery.
Detects the use of PowerShell or Windows Script Host to access files within common web browser cache directories combined with indicators of Base64 decoding and pixel data manipulation. This behavior is indicative of extracting malicious payloads hidden via steganography within browser-cached image files, a technique often used in phishing campaigns to evade detection.
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
Detects the presence of package.json or node_modules artifacts associated with a known typosquatting campaign targeting the 'sorted-btree' npm package. The rule identifies suspicious package names or dependencies by matching against a list of known malicious packages used in the campaign, or by detecting the co-occurrence of the malicious 'indexed-btree' package alongside the legitimate 'sorted-btree' package.
Detects the execution of command-line interpreters (cmd, powershell, mshta, etc.) directly spawned by explorer.exe. This activity is indicative of the 'ClickFix' or 'ConsentFix' attack chain, where a victim is coerced into pasting malicious commands into the Windows Run dialog (Win+R) after interacting with a fraudulent CAPTCHA or verification page in their browser. The rule filters out standard installer-related activity to reduce false positives.
Detects instances where PowerShell or pwsh processes are initiated directly by explorer.exe containing command-line arguments indicative of obfuscated or hidden execution, often used in ClickFix-style social engineering attacks where victims are coerced into pasting malicious commands into the Windows Run dialog.
Page 63 of 1870

