Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
This rule monitors network connections initiated by common web browsers (chrome.exe, msedge.exe, brave.exe) to known domains associated with a specific VPN proxy service or subscription-based proxy farm infrastructure. The rule flags endpoints communicating with URLs involved in proxy beaconing, fallback hosting, and subscription API calls.
Matches archived SHA-256 hashes of known malicious CRX builds from the 'VPN for X' proxy farm extension family
Detects browser-side network activity involving known command-and-control or subscription API domains associated with a malicious VPN browser extension proxy campaign. The rule monitors for beaconing behavior from popular web browsers (Chrome, Edge, Brave) to specific domains utilized by the campaign.
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
Detects evidence of a SharePoint pre-authentication RCE exploit chain where an adversary injects a malicious Namespace containing an ExpandedWrapper-wrapped XamlServices payload (e.g., ObjectDataProvider or LosFormatter gadget) into the w3wp.exe worker process. This specifically looks for command-line arguments indicative of deserialization-based exploit attempts targeting SharePoint web server components.
This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
Page 91 of 1870

