Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
This rule detects a suspicious process chain where wscript.exe or cscript.exe (executing a VBScript file) initiates a PowerShell process with arguments typically used for downloading external content (e.g., Invoke-WebRequest, Net.WebClient), followed by subsequent actions involving remote management tools or installation packages (e.g., MSI files, ConnectWise, ScreenConnect, GoToResolve). This behavior is characteristic of initial access or secondary payload delivery via malicious scripts.
Detects the execution of known Remote Monitoring and Management (RMM) software installers or command-line arguments when invoked by PowerShell processes. This behavior is often indicative of malicious post-compromise activity where an adversary uses legitimate remote access tools to establish persistent command-and-control access.
Detects known file hashes associated with SideCopy/ReverseRAT.
Detects known file hashes associated with SideCopy/ReverseRAT.
This rule detects network activity and cloud API events indicative of an adversary utilizing the VAPI.ai platform to orchestrate automated voice-phishing (vishing) campaigns. It correlates outbound network connections to VAPI.ai endpoints with specific webhook callback patterns used to track call status for victim records.
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
Detects HTML files that employ FlipBook branding as a lure for password-gated smuggling. The detection identifies client-side JavaScript logic that uses PBKDF2 and AES-GCM to decrypt a hidden redirect URL after user interaction with a password prompt.
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
Page 97 of 1870


