Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a suspicious pattern where a single process loads high-risk cryptography and system-level modules (e.g., sqlite3, win32crypt, win32api) followed within 30 minutes by credential harvesting actions such as dumping Wi-Fi keys using 'netsh' or establishing persistence via 'schtasks'. This behavior is indicative of a 'lazy-import' stealer or malicious loader attempting to evade simple signature-based detection.
TokenGrabber Builder: Nuitka/PyInstaller AV-Evasion Compilation - detects Python builder scripts compiling an embedded stealer.py payload into a native executable via Nuitka or PyInstaller with AV-evasion flags
Detects the creation of a Windows scheduled task via schtasks.exe where the initiating process is located in common user-writable temporary or non-standard directories (e.g., AppData, Temp, or Public folders). This behavior is often indicative of malicious persistence mechanisms being established by a dropper or stage-one malware payload.
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
Detects HTTP response bodies containing indicators of 'ClickFix' social engineering lures. The rule monitors for JavaScript code designed to manipulate the user's clipboard (execCommand('copy') or clipboard.writeText) in conjunction with instructions for the user to execute the Windows Run dialog (Win+R), a common technique to trick users into executing malicious commands under the guise of solving a fake CAPTCHA or error.
This rule detects network traffic patterns indicative of the Lumma Stealer 'ClickFix' phishing campaign. It identifies outbound requests to suspicious domains ending in .cyou utilizing specific user agents (WinHttp or Microsoft BITS), which are characteristic of malicious PowerShell scripts attempting to retrieve secondary payloads.
Detects the execution of command interpreters or scripting engines spawned by the ManageEngine ADSelfService Plus GINA client process (typically present at the Windows logon screen). This activity is highly suspicious as it indicates potential command injection or abuse of a pre-authentication component running at SYSTEM privileges.
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
Detects a high volume (more than 5 files within an hour) of potentially executable file types (.lnk, .exe, .vbs) created on non-system drives (D:, E:, F:). This pattern is often associated with the staging of malicious payloads, autorun-based infection attempts, or automated tool deployment from removable or secondary storage.
This rule detects network connections initiated by common Windows administrative or scripting binaries (powershell.exe, cmd.exe, certutil.exe, bitsadmin.exe, mshta.exe) to remote URLs that end with extensions associated with executable content (.exe, .dll, .ps1, .bat). This behavior is often indicative of an adversary performing ingress tool transfer to download and execute malicious payloads.
Detects the compiled x86/x64 fetch-decode-execute dispatch loop used by the Vidar Stealer custom VM bytecode interpreter (v2.0+). The rule identifies the structural jump-table bounds-check and computed-jump idiom that is consistent across different builds of the malware, despite randomization of opcode values and XOR keys.
Detects trojanized versions of Zoom installers that bundle legitimate application installers alongside malicious components including a VBScript persistence mechanism (OneDriveUpdateScheduler) and the VelvetCake PowerShell downloader/C2 framework.
Detects the Exvicy 'ClickFix' campaign execution chain where explorer.exe spawns a PowerShell process utilizing download commands (e.g., Invoke-WebRequest, Invoke-RestMethod) to interact with known malicious domains or IP addresses, followed by the execution of installers (msiexec.exe) or tools (putty.exe) within a short timeframe.
Detects the execution of script interpreters (powershell, cmd, mshta, etc.) spawned directly by explorer.exe via the Run dialog, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands to bypass security mechanisms.
Detects the use of package installation commands (pip, npm, npx) where the package name resembles popular AI/ML libraries (tensorflow, torch, openai, langchain) but is not an exact match for known legitimate versions. This is a common indicator of a typosquatting supply chain attack, where attackers attempt to trick users into installing malicious packages with similar names to trusted software.
Detects the installation of known AI-powered coding assistant extensions (e.g., Copilot, Tabnine, Cursor) on a device, followed by significant source-code repository cloning or archival activity by Git within two hours. This pattern is potentially indicative of intellectual property theft or sensitive source code exfiltration facilitated by a newly introduced AI tool.
This rule detects outbound network connections originating from managed devices where the remote URL or domain matches known underground LLM-based services, such as WormGPT, FraudGPT, or EvilGPT, which are often used by threat actors for malicious activities like generating phishing content or malware.
This rule detects the use of headless or automated web browser tooling (such as Selenium, Puppeteer, Playwright, or browser-specific drivers like chromedriver) establishing network connections to popular generative AI websites. This behavior can indicate automated interaction with AI services, potential data exfiltration of internal information, or unauthorized automation.
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
Page 68 of 1870



