Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
22 detections
Filters
Last updated
All Time
Detection languages
11
7
4
Contributors
22
Categories
10
5
5
5
4
Platforms
19
5
2
1
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
7
7
3
3
3
Detects access to the AWS CLI credentials file (~/.aws/credentials) in a user's home directory, used by CISA's red team to harvest long-lived static IAM access keys.
Detects access to files containing cleartext credentials on an administrative workstation, followed by their use to authenticate to a sensitive business system — the initial-access path CISA's red team used against SBS 1.
Detects process execution shortly after a user clicks a malicious link delivered via spearphishing email, indicating successful initial-access payload execution.
Detects an executable loading an unexpected DLL, indicative of DLL side-loading used to execute a payload while evading static EDR signatures, as observed in CISA's red team engagement.
Detects access to SQL developer tool configuration files (connections.json, product-preferences.xml) followed by a decryption utility, used by CISA's red team to recover cleartext database credentials from a targeted workstation.
Detects the BYOVD kill chain for the DCRCVDrv.sys driver: drop to C:\Windows\Temp\, DCRCVDRV_U/LEGACY_DCRCVDRV_U service installation, device open, and IOCTL 0x2205c0 invocation used to terminate security/EDR processes from kernel context.
Detects the full process-hollowing sequence (suspended process creation, SetThreadContext, ResumeThread) executed against the same target PID for wab.exe or MSBuild.exe within a short window — the ACRStealer campaign's injection technique.
Detects a concentrated sweep of multiple browser credential/cookie artifacts (Local State, Login Data, Cookies, History) by a single non-browser process (OptiDrive.exe) within a one-minute window — the ACRStealer credential-theft stage.
Detects APC injection into dllhost.exe unbacked/private memory via NtQueueApcThread correlated with a subsequent outbound network connection from the same process — the ACRStealer injection-and-C2 pattern.
Detects Run key persistence for follow-on ACRStealer payloads (creator-ws.exe under ProgramData\Rapid, pgocvt.exe under ProgramData\TIEmounter) launched via a cmd /c start wrapper.
Detects wscript.exe executing OptiDrive.vbs from the %LOCALAPPDATA%\DriveOptimize Technologies\ masquerade directory to invoke the renamed AutoIt interpreter OptiDrive.exe — the ACRStealer staging/masquerade technique.
Detects sandbox/VM fingerprinting via combined Win32_DiskDrive and Win32_VideoController WMI queries from the same process/host within a short window — anti-analysis behavior observed in the ACRStealer AutoIt payload prior to execution.
Detects rapid self-deletion of the initial ACRStealer payload artifacts (Proper.a3x, BrowserMetrics) within 5 minutes of their creation by the setup_patched.exe/AutoIt execution chain — an indicator-removal behavior.
Detects non-interactive PowerShell launched via the Sysnative path with -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command - reading commands from stdin — the ACRStealer payload's command-execution technique.
Static file-based detection of the ACRStealer dropper, encrypted AutoIt payload, and DCRCVDrv.sys BYOVD driver via filenames, service/device names, signer names, and certificate serial. Certificate/signer matches only fire in combination with the driver file or service artifacts to avoid flagging the legitimate vendor certificate alone.
Detects DLL side-loading of the unsigned tbbmalloc.dll by the signed binary pgocvt.exe from the C:\ProgramData\TIEmounter\ staging directory — a second-stage follow-on payload technique in the ACRStealer campaign.
Detects an unsigned/unexpected PAM module written into the su/sudo authentication stack, correlated with non-package-manager modification of /etc/pam.d/ configuration and subsequent su/sudo activity — the technique Jewelbug's Linux tooling uses to steal credentials.
Detects execution of AutoIt3.exe running the Proper.a3x payload following extraction by the IExpress self-extractor setup_patched.exe (or from its IXP000.TMP staging path) — the initial infection chain observed in the ACRStealer/Amatera BYOVD campaign.
Detects ELF binaries embedding the ClientKing implant name alongside structural indicators (Rust runtime markers or C2 configuration patterns), associated with Jewelbug espionage tooling targeting Linux servers and routers
Detects mshta.exe execution combined with CSIS geopolitical lure content or the known TEST.hta downloader artifact used to deliver the Antino backdoor
Detects ClientKing's technique of loading Linux kernel modules directly from memory (via memfd/init_module) without a corresponding on-disk .ko file, used to deploy rootkit functionality.
Page 1 of 2
