Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects registry value modifications to the Windows Explorer RunMRU key where the data contains indicators of obfuscated PowerShell commands. This pattern is commonly associated with the 'ClickFix' social-engineering campaign, where users are prompted to copy and paste a malicious PowerShell command into the Windows Run dialog.
Detects the abuse of Windows protocol handlers ('search-ms:') and WebDAV UNC paths ('@SSL\DavWWWRoot') launched from common web browsers or Windows shell processes. This technique, frequently observed in 'ClickFix' phishing campaigns, enables attackers to stage remote payloads like LNK, HTA, or scripts by leveraging native Windows functionality to resolve remote content as if it were a local resource, bypassing typical file download security controls.
Detects instances where a suspected malicious loader initiates process hollowing or APC injection by launching trusted Windows binaries (e.g., LockAppHost.exe, makecab.exe, Magnify.exe) in a suspended state. The rule identifies suspicious post-injection behavior such as unexpected network connections or child process creation originating from these typically benign binaries, which is characteristic of the DeepLoad/ClickFix attack chain.
Detects a suspected ClickFix-style delivery mechanism where a user visits suspicious domains mimicking legitimate CLI tools (e.g., Gemini, Claude) via web browsers. The detection correlates this initial network access with subsequent suspicious Windows RunMRU activity and the spawning of shell processes (powershell.exe, cmd.exe) from explorer.exe using encoded or download-oriented command line arguments within a 5-minute window.
Detects multiple reconnaissance commands executed by PowerShell processes running as the SYSTEM account. This behavior is indicative of an attacker attempting to enumerate domain trusts, group memberships, or user sessions on a host to facilitate lateral movement or privilege escalation.
Detects the execution of 'sqlcmd.exe' when spawned by web application pools (w3wp.exe) or general command shell (cmd.exe) processes that do not appear to be related to authorized database administration or IIS appcmd activity.
Detects the use of 'findstr' or PowerShell to query sensitive configuration files (such as web.config or applicationHost.config) for credential-related keywords like 'connectionString', 'AccountKey', or 'machineKey'. This behavior is indicative of an adversary attempting to harvest credentials or sensitive configuration data stored in cleartext on the filesystem.
Detects the Microsoft IIS worker process (w3wp.exe) spawning common command-line shells (cmd.exe or powershell.exe) and executing discovery-related commands. This is highly indicative of potential web shell activity where an adversary uses an existing web application vulnerability to gain remote code execution.
Detects the presence of known SHA256 hashes associated with the 'ccrtc' planter PowerShell scripts and C2 SDK JavaScript components. These files were identified as being dropped into 'C:\Windows\Temp' during the STAC4924 webshell intrusion campaign.
Detects the creation of an ASPX file within a member file upload directory, followed immediately by the execution of 'cmd.exe' by the 'w3wp.exe' web server process. This behavior is indicative of a web shell being uploaded and used to execute arbitrary commands on the server.
Detects reconnaissance activity on IIS servers where the worker process (w3wp.exe) spawns appcmd.exe or PowerShell to list websites, virtual directories, or application pools. This pattern is indicative of an attacker performing post-exploitation discovery after establishing a web shell.
Detects instances where a Microsoft IIS worker process (w3wp.exe) executes commands such as 'findstr', 'Get-Content', or 'Select-Xml' to scan configuration files (e.g., applicationHost.config, web.config) or source code files (e.g., App_Code/*.cs) for sensitive information like passwords, connection strings, or API keys. This behavior is indicative of credential harvesting by an attacker using a webshell or compromised IIS process.
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates a child process of sqlcmd.exe. This behavior is highly suspicious and often indicates a post-exploitation activity where an attacker, having established a webshell or similar foothold on a web server, is using harvested credentials to query backend SQL databases directly.
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates a child process of sqlcmd.exe. This behavior is highly suspicious and often indicates a post-exploitation activity where an attacker, having established a webshell or similar foothold on a web server, is using harvested credentials to query backend SQL databases directly.
Detects instances where an IIS worker process (w3wp.exe) spawns a command shell (cmd.exe) that executes a conditional file copy operation. This pattern is characteristic of an adversary creating a webshell by copying a payload to a filename that masquerades as a legitimate web application asset, such as a CSS bundle or validation script.
This rule monitors for suspicious command-line activity involving the Fortis payment processor's webhook log files. It detects when attackers use tools like 'findstr', 'cmd', or 'dir' to navigate directories containing webhook data and specifically searches for payment card fields such as CVV, primary account numbers, and expiration dates, which is a common indicator of post-compromise data exfiltration.
Detects DLL sideloading activity associated with the 'Lorem Ipsum Loader' malware. The rule monitors for specific combinations of legitimate Windows binaries loading specific DLLs from non-system directories, a common technique to execute malicious code via trusted processes.
This rule detects HTTP requests where the User-Agent header indicates a PowerShell execution occurring from a system configured with the zh-CN locale. This pattern is often associated with automated scripts or potential malicious activity masquerading as legitimate PowerShell traffic.
Detection of common web server reconnaissance, enumeration, and brute-force patterns targeting IIS environments. This includes detection of short-name (~1) probes, WebDAV method usage, NTFS alternate data stream requests, and brute-force attempts on login endpoints originating from PowerShell user agents.
Detects the presence of an embedded word-to-hex lookup table within a PE file. This technique is used by the Lorem Ipsum Loader to store shellcode as plaintext English words to evade entropy-based detection and static analysis tools. The rule matches a dense sequence of lowercase words frequently found in these malicious loaders.
The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks.
Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the
symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact,
its alternate data stream, and their subsequent removal.
Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the
symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact,
its alternate data stream, and their subsequent removal.
Page 64 of 1870

