Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects bulk or repeated attempts to stop security-related services and processes (such as EDR or AV agents) or modification of Windows Defender registry keys. This behavior is indicative of a pre-encryption phase in ransomware attacks where adversaries attempt to neutralize endpoint defenses.
Detects the use of legitimate data-transfer utilities (rclone, MEGA client, restic, WinSCP) configured to exfiltrate data to cloud storage providers. This behavior is identified as a precursor to double-extortion ransomware attacks, where attackers steal sensitive data before encrypting it.
Detects browser processes performing JSON-RPC network connections to known public blockchain node providers, a network behavior characteristic of the EtherHiding technique used by the ErrTraffic MaaS platform to resolve C2 infrastructure via smart contracts. This rule identifies the network-side beaconing and should be correlated with suspicious process execution chains (e.g., browser-spawned PowerShell/cmd).
Detects the execution of PowerShell or MSHTA from explorer.exe with command line arguments indicative of malicious activity, such as hidden windows, Base64 encoding, or command execution (IEX/Invoke-Expression). This behavior is common in fileless malware delivery and script-based initial access.
This rule detects the execution of the Cloudflare 'cloudflared' utility from non-standard directory locations. Cloudflared is often abused by threat actors to establish reverse tunnels (e.g., TryCloudflare) to gain unauthorized, persistent, and encrypted external access to a compromised host, effectively bypassing standard perimeter network security controls.
This rule detects instances where common system processes (svchost.exe, explorer.exe, dllhost.exe) perform process injection activities, followed within a 5-minute window by a network connection to known SaaS and collaborative platforms (Slack, Discord, Dropbox, Trello). This combination is often indicative of malicious code executing within a trusted process to facilitate command and control or data exfiltration.
This rule detects the execution of common remote access and RMM (Remote Monitoring and Management) tools spawned directly from web browser processes (e.g., Chrome, Edge, Firefox). It further monitors for subsequent suspicious child process activity such as command shell execution or file operations performed by these RMM tools, which is a common pattern in post-exploitation and initial access activities.
This rule detects potentially malicious PowerShell, CMD, or PWSH command execution characterized by obfuscation techniques (such as Base64 encoding, decompression, or hidden command arguments) that are followed closely in time by network connections to public AI service domains (OpenAI, Anthropic, Google Generative Language, Mistral, Cohere). The detection correlates process-start events with outbound network requests from processes other than standard web browsers, suggesting potentially unauthorized use of AI APIs for exfiltration or automated processing of command results.
This rule detects the suspicious loading of known vulnerable drivers (Bring Your Own Vulnerable Driver - BYOVD) via the Windows service control manager (sc.exe) or event log 7045, followed by the immediate termination of major endpoint security software processes within a 300-second window. This behavior is indicative of an attempt to disable or tamper with security tools using kernel-level privileges.
Detects the creation or writing of disk image files (.iso, .img, .vhd, .vhdx) followed by the execution of suspicious file types (.lnk, .exe, .js, .vbs, .cmd, .bat, .scr) by explorer.exe within a 10-minute window. This behavior is indicative of an adversary using container files to bypass security controls or execute malicious payloads from mounted images.
Detects suspicious administrative activity involving privileged users performing bulk account/object deletions or stopping critical identity-related services (ADFS, Active Directory Certificate Services). The rule specifically flags events occurring outside standard business hours, involving privileged AD groups, or directly targeting identity infrastructure, indicating a potential attempt to disrupt authentication services or sabotage identity management.
Detects anomalous mass file modification or renaming activity often associated with ransomware, combined with the deletion of Windows Volume Shadow Copies using native utilities like vssadmin or wmic, and the presence of suspicious ransom note filenames.
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
Page 94 of 1870
