Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects legitimate, signed executables from trusted system locations (e.g., System32) loading DLLs from non-standard, user-writable directories (e.g., Temp, AppData). This activity is a classic indicator of DLL side-loading, where an adversary places a malicious DLL in a directory to be picked up by a legitimate application, enabling the execution of malicious code under the context of a trusted process.
Detects suspicious cross-process memory operations where a source process requests process creation/write permissions on a target process (e.g., browsers, explorer.exe, or svchost.exe), followed immediately by the execution of a remote thread injection technique such as CreateRemoteThread, QueueUserAPC, or NtCreateThreadEx within the same process pair.
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
Detects the use of the built-in Windows utility rundll32.exe to execute the MiniDump functionality within comsvcs.dll against the Local Security Authority Subsystem Service (LSASS). This technique is a common method for attackers to bypass signature-based security tools and obtain sensitive credentials from memory.
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
Detects the abuse of the legitimate Windows system binaries regsvr32.exe and rundll32.exe to execute remote scripts or scriptlets, a technique often used to bypass application control and proxy execution of malicious code (similar to Squiblydoo).
Detects the execution of reg.exe with the 'save' command to extract the SAM, SYSTEM, or SECURITY registry hives to disk. This technique is commonly used by attackers to offline extract credential hashes, facilitating pass-the-hash attacks and lateral movement.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
Detects the execution of PowerShell with encoded commands (e.g., -EncodedCommand or -enc) combined with common download cradle indicators such as IEX, Net.WebClient, or DownloadString. This combination is highly indicative of fileless malware execution, initial access payload staging, or defense evasion techniques often employed by threat actors to bypass command-line monitoring.
Detects unauthorized directory replication requests (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) made against Active Directory by a user or computer account that is not a domain controller. This behavior is indicative of a DCSync attack, typically performed by tools like Mimikatz to extract password hashes for all domain accounts.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the task is configured to run in the security context of the SYSTEM account or executes suspicious binaries like PowerShell, mshta, or other living-off-the-land binaries. This behavior is indicative of potential persistence mechanisms employed by adversaries.
Detects the abuse of the built-in Windows utility 'certutil.exe' to download remote files using URL cache functionality or to deobfuscate base64-encoded payloads. This is a common LOLBin (Living-off-the-Land Binary) technique used in phishing loaders, malware delivery, and post-exploitation toolkits.
Detects the creation of WMI permanent event subscriptions, including the instantiation of __EventFilter, __EventConsumer, and __FilterToConsumerBinding classes. This mechanism is frequently used by adversaries for fileless and reboot-resilient persistence, as it allows for arbitrary code execution triggered by system events.
This rule detects potential Kerberoasting activity by monitoring Windows Security Event ID 4769 for TGS service ticket requests using weak RC4 encryption (etype 0x17). It correlates these individual requests to identify a single user account requesting an abnormally high volume of service tickets within a 10-minute window, which is highly characteristic of automated SPN enumeration and cracking tools like Rubeus or Impacket.
Detects instances where a digitally signed executable loads a DLL from a non-standard, user-writable directory (such as Downloads, Desktop, Temp, or AppData). This behavior is characteristic of DLL side-loading, an evasion technique used to execute malicious code by placing a rogue DLL in a location where a legitimate binary might search for its dependencies, often used by threat actors to persist or maintain covert execution.
Detects lateral movement activities involving the use of PsExec-style tools or the manual creation of remote services to execute commands. This behavior often leverages SMB admin shares (ADMIN$, C$) to drop and execute binaries or scripts, a technique frequently observed in ransomware campaigns and red team engagements.
This rule detects artifacts and command-line patterns associated with Impacket utility suite modules, specifically wmiexec.py, smbexec.py, and secretsdump.py. These tools are commonly used by adversaries for remote command execution, lateral movement, and dumping of sensitive domain or system credentials.
Detects the execution of legitimate developer utilities msbuild.exe, regasm.exe, and regsvcs.exe in manners consistent with malicious proxy execution. This includes the use of inline tasks in project files, remote network-sourced project files, or specific command-line arguments (such as /codebase or /unregister) that suggest the abuse of these binaries to execute arbitrary code or bypass application control mechanisms, while excluding known legitimate developer-related parent processes and build workflows.
Detects Microsoft Office applications or scripting engines spawning schtasks.exe to create or modify a scheduled task that executes as the SYSTEM user upon system startup or login. This behavior is highly indicative of persistence mechanisms used by malicious documents or scripts.
Page 77 of 1870

