Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule monitors for DNS queries and network connections to a known list of malicious domains associated with phishing campaigns that deploy remote access tools (such as ScreenConnect or MSP360). These campaigns typically involve users interacting with malicious links to trigger downloads or remote management sessions.
Detects the presence or execution of known malicious Remote Monitoring and Management (RMM) tool binaries associated with phishing campaigns, such as those impersonating MSP360 or ScreenConnect.
Detects the presence or execution of known malicious Remote Monitoring and Management (RMM) tool binaries associated with phishing campaigns, such as those impersonating MSP360 or ScreenConnect.
This rule monitors for DNS queries and network connections to a known list of malicious domains associated with phishing campaigns that deploy remote access tools (such as ScreenConnect or MSP360). These campaigns typically involve users interacting with malicious links to trigger downloads or remote management sessions.
Detects the execution of MSP360 or generic RMM-labeled binaries originating from common user download directories (Downloads or Temp folders) when the filename mimics common phishing lures such as invoice, e-card, RSVP, or document-related naming conventions. This activity indicates a potential social engineering attempt to execute remote monitoring and management tools.
Detects instances where a legitimate Remote Monitoring and Management (RMM) agent (MSP360 or Faronics) is used to execute PowerShell commands that silently install ScreenConnect (ConnectWise Control) MSI packages within a 10-minute window. This behavior is indicative of an adversary abusing administrative tools for lateral movement or persistence.
This rule detects the execution of potentially malicious binaries masquerading as legitimate Windows utilities (e.g., Windows Update, Defender, or Phone Link) from within a ScreenConnect temporary directory. This behavior is indicative of a phishing attack where an adversary uses remote access tools to stage and execute malicious payloads on a victim's system.
Detects potential persistence and network persistence mechanisms associated with the MSP360 RMM agent. The rule correlates the creation of a Windows service for RMM.Agent.exe or RMM.Agent.Launcher.exe with the addition of a firewall rule allowing UDP traffic on port 48678 by netsh or PowerShell, occurring within a one-hour window.
Detects the presence or execution of known malicious Remote Monitoring and Management (RMM) tool binaries associated with phishing campaigns, such as those impersonating MSP360 or ScreenConnect.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Detects the abuse of the Windows Scripted Diagnostics framework (sdiagnhost.exe) by the Antino threat actor. The attack leverages sdiagnhost.exe to proxy the execution of a malicious script (result.ps1) that subsequently establishes persistence by creating a Registry Run key (GatherOSStateKit). The rule correlates the execution of the scripted diagnostic package with the specific registry modification event within a 5-minute window.
Detects the abuse of the Windows Scripted Diagnostics framework (sdiagnhost.exe) by the Antino threat actor. The attack leverages sdiagnhost.exe to proxy the execution of a malicious script (result.ps1) that subsequently establishes persistence by creating a Registry Run key (GatherOSStateKit). The rule correlates the execution of the scripted diagnostic package with the specific registry modification event within a 5-minute window.
Detects the abuse of the Windows Scripted Diagnostics framework (sdiagnhost.exe) by the Antino threat actor. The attack leverages sdiagnhost.exe to proxy the execution of a malicious script (result.ps1) that subsequently establishes persistence by creating a Registry Run key (GatherOSStateKit). The rule correlates the execution of the scripted diagnostic package with the specific registry modification event within a 5-minute window.
Detects the abuse of the Windows Scripted Diagnostics framework (sdiagnhost.exe) by the Antino threat actor. The attack leverages sdiagnhost.exe to proxy the execution of a malicious script (result.ps1) that subsequently establishes persistence by creating a Registry Run key (GatherOSStateKit). The rule correlates the execution of the scripted diagnostic package with the specific registry modification event within a 5-minute window.
Detects the abuse of the Windows Scripted Diagnostics framework (sdiagnhost.exe) by the Antino threat actor. The attack leverages sdiagnhost.exe to proxy the execution of a malicious script (result.ps1) that subsequently establishes persistence by creating a Registry Run key (GatherOSStateKit). The rule correlates the execution of the scripted diagnostic package with the specific registry modification event within a 5-minute window.
Detects activity associated with the MALFEX npm supply-chain campaign (also known as Overlord/movinlike). This rule performs a sweep for known malicious file hashes, suspicious process command lines, outbound network connections to malicious domains or IPs, and email communications from identified adversary-controlled accounts.
Detects the installation or execution of known MALFEX malicious packages via npm or Node.js, which are used as entry points for polyglot or disguised payload delivery.
Detects the installation or execution of known MALFEX malicious packages via npm or Node.js, which are used as entry points for polyglot or disguised payload delivery.
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
Page 86 of 1870

