Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the UAT-11587 TestAssembly.dll downloader by its shared AssemblyAttribute GUID b2b3adb0-1669-4b94-86cb-6dd682ddbea3 embedded in .NET metadata across all campaign builds
Detects Antino backdoor binaries (slc.dll and standalone) via embedded AntinoApp application manifest string and Rust PDB path patterns matching GitHub Actions Windows runner structure.
Detects UAT-11587 diplomatic-lure LNK file exploiting ZDI-CAN-25373 whitespace padding to conceal a PowerShell command that extracts CanonStager (cnmpaui.exe/dll) from TAR archives into %TEMP%
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Page 89 of 1870

