Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects suspicious processes such as PowerShell, Python, or scripting hosts performing network communication with major AI/LLM provider APIs, followed immediately by child process execution or related activity. This pattern is indicative of LLM-assisted automation for malicious activities, potentially using AI to generate code, scripts, or orchestrate command and control actions.
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
Detects the installation of browser extensions that utilize sensitive permissions (e.g., full URL access, cookie access) followed shortly by network connections to potentially non-reputable domains within one hour of the installation. This pattern is indicative of malicious browser extensions established for data exfiltration or credential theft.
Detects high-risk domain account activity, specifically identifying either impossible-travel authentication patterns in cloud logs or rapid, multi-host interactive authentication fan-out within one hour. These detections are further correlated with subsequent RDP or WinRM session establishment, indicating potential lateral movement or compromise of legitimate accounts.
Detects processes querying registry keys or accessing file paths associated with common virtualization and sandbox environments (e.g., VMware, VirtualBox, Hyper-V, Sandboxie). This behavior is often indicative of malware attempting to identify if it is running in an analysis or sandbox environment to evade detection.
Detects attempts to disable, stop, or reconfigure security software (Antivirus, EDR, Endpoint Protection) on Windows endpoints by abusing legitimate administrative utilities such as sc.exe, net.exe, taskkill.exe, wmic.exe, and PowerShell to tamper with service configurations or kill security-related processes.
Detects potential exploitation of Active Directory Certificate Services (AD CS) misconfigurations (specifically ESC1, involving client-auth EKU and enrollee-supplies-subject). The rule correlates certificate issuance events (4886, 4887, 4888) involving sensitive templates or suspicious subject alternative name (SAN) mismatches with subsequent Kerberos PKINIT authentication (4768) events using the issued certificate.
Detects a potential mass-encryption event by identifying a single host rapidly renaming or rewriting a large volume of files across multiple SMB network shares within a short timeframe, where the renamed files consistently adopt a single file extension.
Detects lateral movement via SMB by identifying multiple connections to Windows admin shares (ADMIN$ or C$) followed within a 10-minute window by the creation of a remote service, often indicative of techniques like PsExec. This pattern detects suspicious fan-out behavior where a single source host interacts with multiple targets.
Detects the creation of scheduled tasks via schtasks.exe or native Windows event logs that exhibit suspicious characteristics commonly associated with persistence mechanisms. These characteristics include tasks triggered at logon or system startup, tasks running with elevated SYSTEM privileges, tasks configured to be hidden, or tasks executing binaries from temporary, user-writable directories (Temp, AppData, Public). This pattern is often observed in attack chains leveraging RMM tools or delivery mechanisms like ClickFix.
Detects common Windows system binaries (svchost.exe, csrss.exe, lsass.exe, explorer.exe) executing from non-standard directories, which is a common indicator of process masquerading to evade detection.
This rule detects unauthorized or unauthenticated attempts to call the NetrServerPasswordSet2 method on a Domain Controller via the MS-NRPC (Netlogon) interface, which is indicative of an exploitation attempt related to CVE-2020-1472 (Zerologon). This vulnerability allows an attacker to bypass authentication and reset a Domain Controller's computer account password, leading to full domain compromise.
Detects the execution of LNK files masquerading as PDF files through the use of double extensions (e.g., .pdf.lnk). The rule monitors for processes spawned by explorer.exe that contain '.pdf.lnk' in the command line and trigger child processes like PowerShell, CMD, WScript, or MSHTA, which are common indicators of malicious intent.
Detects a coordinated attack sequence where a browser process is terminated, followed immediately by the execution of an unsigned Python interpreter from a suspicious location (temp/downloads folder), which is then followed by the installation of an unsigned browser extension. This pattern mimics ClickFix and browser-based RAT lure campaigns.
Detects network traffic indicative of VelvetCake malware exfiltrating data. The rule specifically monitors for HTTP POST requests to 'logout.php' containing 'OKey' and 'Who' parameters, using a user agent string that includes 'WebClient', which is often associated with PowerShell-based network requests.
Page 95 of 1870
