Browse Rules

Search and filter across all detection sources

56,959 rules

falconforce unknown kql

User-Execution

falconforce unknown kql

Browser Extensions - Chrome Extensions

falconforce unknown kql

Masquerading: Invalid Code Signature - Network Connections

falconforce unknown kql

Remote Services: Distributed Component Object Model

elastic high eql

Potential EtherHiding C2 via Curl JSON-RPC Request

Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.

elastic low eql

Launch Service Creation and Immediate Loading

An adversary can establish persistence by installing a new launch agent that executes at login by using launchd or launchctl to load a plist into the appropriate directories.

elastic high kql

Multiple Alerts Involving a User

This rule uses alert data to determine when multiple different alerts involving the same user are triggered. Analysts can use this to prioritize triage and response, as these users are more likely to be compromised.

elastic high eql

Potential Etherhiding C2 via Blockchain Connection

Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware.

elastic high kql

Potential Entra ID PRT Extraction via BrowserCore

Identifies anomalous execution of BrowserCore.exe, the Windows component used by Chromium-based browsers for native messaging with the Web Account Manager (WAM). Adversaries abuse BrowserCore to extract Entra ID Primary Refresh Tokens (PRTs) without interactive browser context, enabling session hijacking. Legitimate BrowserCore launches carry a chrome-extension:// argument from the browser native-messaging host.

elastic medium kql

AWS Root Console Login Password Spraying

Identifies failed authentication attempts against the AWS Management Console root user from the same source IP address targeting multiple AWS accounts. Password spraying uses few attempts per target across many accounts to avoid lockout, making per-account volume an unreliable signal. This rule detects the cross-account breadth pattern: a single source IP generating root ConsoleLogin failures across two or more distinct AWS accounts. Requires an AWS Organizations-level CloudTrail trail aggregati

elastic medium eql

Installation of Custom Shim Databases

Identifies the installation of custom Application Compatibility Shim databases. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes.

elastic low eql

Potential Application Shimming via Sdbinst

The Application Shim was created to allow for backward compatibility of software as the operating system codebase changes over time. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes.

elastic high eql

Potential Masquerading as System32 DLL

Identifies suspicious instances of default system32 DLLs either unsigned or signed with non-MS certificates. This can potentially indicate the attempt to masquerade as system DLLs, perform DLL Search Order Hijacking or backdoor and resign legitimate DLLs.

loldrivers low sigma

Driver Load - 1109.sys

Detects loading of driver 1109.sys via name. 1109.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers high sigma

Driver Load - 1109.sys

Detects loading of driver 1109.sys via hash. 1109.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers medium sigma

Driver Load - 1fc7aeeff3ab19004d2e53eae8160ab1.sys

Detects loading of driver 1fc7aeeff3ab19004d2e53eae8160ab1.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 1fc7aeeff3ab19004d2e53eae8160ab1.sys

Detects loading of driver 1fc7aeeff3ab19004d2e53eae8160ab1.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers low sigma

Driver Load - 1.sys

Detects loading of driver 1.sys via name.

loldrivers medium sigma

Driver Load - 2.sys

Detects loading of driver 2.sys via name. Driver categorized as POORTRY by Mandiant.

loldrivers high sigma

Driver Load - 2.sys

Detects loading of driver 2.sys via hash. Driver categorized as POORTRY by Mandiant.

loldrivers low sigma

Driver Load - 360netmon_wfp.sys

Detects loading of driver 360netmon_wfp.sys via name. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.

loldrivers high sigma

Driver Load - 360netmon_wfp.sys

Detects loading of driver 360netmon_wfp.sys via hash. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.

loldrivers medium sigma

Driver Load - 4118b86e490aed091b1a219dba45f332.sys

Detects loading of driver 4118b86e490aed091b1a219dba45f332.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 4118b86e490aed091b1a219dba45f332.sys

Detects loading of driver 4118b86e490aed091b1a219dba45f332.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 4748696211bd56c2d93c21cab91e82a5.sys

Detects loading of driver 4748696211bd56c2d93c21cab91e82a5.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel