Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
This rule monitors for the creation of known Neo-reGeorg web shell files ('tunnel.jsp', 'tunnel.jspx') within common web server directory paths, such as 'webapps', 'applications', 'wlserver', 'PSHTTP', 'PORTAL', or 'webserv'. Neo-reGeorg is a popular tunneling web shell used by adversaries to facilitate persistent access and proxy traffic into a compromised environment.
Detects the execution of the SIDEEYE backdoor (Ple64.exe) when it is spawned by web-based processes such as Java (WebLogic) or shell interpreters (cmd.exe/powershell.exe) invoked by web-based parents. This behavior is indicative of a web shell exploitation attempt.
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
This rule detects a sequential multi-stage execution chain starting with msiexec.exe launching a hidden PowerShell script, followed by wscript.exe executing a VBScript agent, and finally node.exe executing a JavaScript file within a short time window. This pattern is indicative of a complex, multi-stage dropper or malware execution flow.
Detects the loading of a known malicious 136KB browser injection helper DLL (SHA256: 75018b06c7105a1dca391805d17b402aed35ebd515b92d461236eafbd606cb40) into Google Chrome or Microsoft Edge processes. The rule further correlates this activity with command line arguments indicative of abusing the browser's elevation service, which is a technique often used for process injection or local privilege escalation.
Detects the deletion of Chrome registry keys related to extension integrity verification. This behavior is often associated with browser-based attacks, such as malware or malicious extensions attempting to tamper with browser security configurations to enable persistent browser hijacking or unauthorized extension modification.
Detects the ChainScript RAT agent (executing as node.exe from specific masquerading directory paths) scanning for and enumerating cryptocurrency wallet files, browser-stored wallet extensions, and related sensitive configuration data.
Detects the installation or configuration of the NvFsFilter (Alinubx.sys) persistence driver, often associated with malicious behavior that continuously terminates security software processes to allow for persistent unauthorized activity after system reboots.
This rule detects the loading of the known vulnerable NvFsFilter (Alinubx) driver, followed by the abrupt cessation of multiple active AV/EDR processes within a 30-minute window. This behavior is indicative of a Bring Your Own Vulnerable Driver (BYOVD) attack, where the driver is used to execute kernel-mode commands to terminate security software, bypassing standard protection mechanisms.
Detects the execution of MSI installers from user-writable directories (e.g., Downloads, Temp, Public) that masquerade as legitimate software applications like Spotify, Zoom, or Microsoft Teams. This behavior is indicative of 'ClickFix' style social engineering lures, where users are prompted to download and execute malicious installers.
Detects the installation of a Windows service that mimics the legitimate NVIDIA File System Filter Driver (NvFsFilter). Adversaries, such as those associated with the Rapuncel infostealer, use this technique to establish persistence and evade security controls by masquerading as a common driver component.
Page 99 of 1870


