Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,719 detections
Filters
Last updated
All Time
Detection languages
14,958
13,681
2,584
1,830
1,753
Contributors
7,678
6,007
5,304
4,504
3,924
Categories
17,809
9,464
3,730
3,649
3,647
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,086
9,489
6,964
1,880
1,704
MITRE Techniques
13,685
12,943
8,046
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects potential malicious activity by monitoring for specific file hashes, specific suspicious filenames, and suspicious command-line patterns (e.g., 'antivm') initiated by known update or launcher processes. This is likely an indicator of malware behavior involving anti-sandbox or evasion techniques.
This rule detects potential malicious activity by monitoring for specific file hashes, specific suspicious filenames, and suspicious command-line patterns (e.g., 'antivm') initiated by known update or launcher processes. This is likely an indicator of malware behavior involving anti-sandbox or evasion techniques.
This rule detects potential malicious activity by monitoring for specific file hashes, specific suspicious filenames, and suspicious command-line patterns (e.g., 'antivm') initiated by known update or launcher processes. This is likely an indicator of malware behavior involving anti-sandbox or evasion techniques.
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
This rule detects potentially malicious activities aimed at credential harvesting and system recovery inhibition. It monitors for the execution of vssadmin.exe with arguments to list shadow copies (often a precursor to deletion) or references to DPAPI master keys in command lines. Additionally, it identifies unauthorized processes attempting to access sensitive browser-based credential files (e.g., Login Data, Cookies, key4.db) from standard browser installation paths, specifically excluding legitimate browser and update processes.
This rule detects potentially malicious activities aimed at credential harvesting and system recovery inhibition. It monitors for the execution of vssadmin.exe with arguments to list shadow copies (often a precursor to deletion) or references to DPAPI master keys in command lines. Additionally, it identifies unauthorized processes attempting to access sensitive browser-based credential files (e.g., Login Data, Cookies, key4.db) from standard browser installation paths, specifically excluding legitimate browser and update processes.
This rule detects potentially malicious activities aimed at credential harvesting and system recovery inhibition. It monitors for the execution of vssadmin.exe with arguments to list shadow copies (often a precursor to deletion) or references to DPAPI master keys in command lines. Additionally, it identifies unauthorized processes attempting to access sensitive browser-based credential files (e.g., Login Data, Cookies, key4.db) from standard browser installation paths, specifically excluding legitimate browser and update processes.
This rule detects potentially malicious activities aimed at credential harvesting and system recovery inhibition. It monitors for the execution of vssadmin.exe with arguments to list shadow copies (often a precursor to deletion) or references to DPAPI master keys in command lines. Additionally, it identifies unauthorized processes attempting to access sensitive browser-based credential files (e.g., Login Data, Cookies, key4.db) from standard browser installation paths, specifically excluding legitimate browser and update processes.
This rule detects potentially malicious activities aimed at credential harvesting and system recovery inhibition. It monitors for the execution of vssadmin.exe with arguments to list shadow copies (often a precursor to deletion) or references to DPAPI master keys in command lines. Additionally, it identifies unauthorized processes attempting to access sensitive browser-based credential files (e.g., Login Data, Cookies, key4.db) from standard browser installation paths, specifically excluding legitimate browser and update processes.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
Detects NeedleStealer Go-based stealer payload via embedded module path, internal API namespace, build tag, and C2 backend domain
Detects NeedleStealer Go-based stealer payload via embedded module path, internal API namespace, build tag, and C2 backend domain
