Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the execution of 'LevelInstaller.exe' with specific installation arguments ('--action install --force --key') in conjunction with the presence of the 'level.exe' binary in its designated Program Files directory. The rule optionally identifies related scheduled task creation for 'Level Watchdog' and network activity associated with the 'level.io' domain or specific IP address.
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
This rule detects rundll32.exe executing a DLL from the ProgramData directory and subsequently establishing five or more outbound network connections to external IP addresses over non-standard ports (excluding 80 and 443) within a one-hour window. This behavior is indicative of a potential malware beaconing or data staging activity using a proxy binary to evade detection.
Detects modifications to the 'PlugPlay' Windows service using 'sc.exe', specifically involving changes to the binary path (binpath) and subsequent service status changes (start/stop) within a short timeframe (30 minutes). This behavior is often associated with the persistence or hijacking of services to execute malicious files, specifically targeting Microsoft Office or Copilot-related process names.
Detects anomalous file activity associated with the PaperCut application (pc-app.exe), characterized by the creation of numbered binary chunks (.bin) followed by the creation of a status log file (pcxboot_l.txt) and the subsequent deletion of the binary chunks. This behavior is indicative of an in-memory Java payload loader pattern used to evade detection.
Detects credential-dumping modules (such as nanodump, hashdump, and lsadump variants) associated with AdaptixC2 framework being invoked or used by the 'mscopilot.exe' process. The rule monitors for command-line arguments indicating credential extraction, unauthorized attempts to open handle to lsass.exe, and access to sensitive registry hives (SAM, Security, LSA) by the suspect process.
Detects the deletion, truncation, or modification of critical PaperCut server logs and application files (server.log, pcxboot_l.txt, .bin files). This activity is associated with attempts to conceal exploitation of PaperCut vulnerabilities (e.g., CVE-2026-82078/81578) by clearing logs or tampering with binaries, typically executed by the PaperCut application processes themselves (pc-app.exe or Java runtime).
This rule detects suspicious activity originating from the PaperCut 'pc-app.exe' process. It monitors for the creation or execution of a file named 'mscopilot.exe' within the non-standard directory 'C:\Microsoft.Office365\'. The rule matches based on a known malicious SHA1 hash or the specific file-write-then-execute behavior within a one-hour window, indicating potential AdaptixC2 loader activity.
Detects instances where the WMI Provider Host (wmiprvse.exe) spawns suspicious child processes such as cmd.exe, powershell.exe, or rundll32.exe, which are correlated with inbound network connections on ports 135 (RPC/DCOM) or 445 (SMB). This behavior is characteristic of lateral movement techniques used by tools like Impacket's wmiexec.
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (lsass.exe) with sensitive access rights (e.g., PROCESS_VM_READ, PROCESS_QUERY_INFORMATION). These access patterns are frequently utilized by credential dumping tools like Mimikatz, ProcDump, or malicious abuse of system utilities to extract plaintext passwords or NTLM hashes from memory.
Detects the execution of PowerShell or PWSH with encoded command flags (-EncodedCommand, -enc, -e), which is a common technique used by adversaries to hide malicious scripts or payloads from inspection.
Page 79 of 1870


