Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
30 detections
Filters
Last updated
All Time
Detection languages
30
Contributors
25
2
1
1
1
Categories
30
26
9
5
4
Platforms
30
4
2
Products / Services
30
28
1
1
MITRE Techniques
26
19
17
6
4
CVEs
12
4
4
4
1
IDS Classtypes
1,896
482
449
381
237
30
IDS Protocols
12
5
4
4
3
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
This rule detects a potential SYN flood denial-of-service attack, characterized by a high volume of TCP SYN packets directed at a target within a short timeframe. Such activity is indicative of attempts to exhaust server resources by leaving TCP handshakes incomplete.
Detects anomalous, oversized fragmented UDP traffic (exceeding 1400 bytes) targeting or originating from the MikroTik btest service port (2000). This behavior is indicative of attempts to trigger integer underflows, system crashes, or uninitialized memory disclosures within the btest protocol implementation.
Detects high-volume POST requests containing HEIF, HEIC, or AVIF image content types, indicative of automated fuzzing or exploitation attempts against an image-processing endpoint targeting CVE-2026-32882.
Detects a specifically malformed IPv6 Routing Header (type 0) with a 'segments_left' value of 255 preceding an Authentication Header (AH). This signature targets an exploit pattern known as 'DirtyAH6', which aims to trigger a remote kernel crash or potential remote code execution on vulnerable systems by manipulating IPv6 header processing.
Detects high-volume POST requests containing HEIF, HEIC, or AVIF image content types, indicative of automated fuzzing or exploitation attempts against an image-processing endpoint targeting CVE-2026-32882.
Detects high-volume POST requests containing HEIF, HEIC, or AVIF image content types, indicative of automated fuzzing or exploitation attempts against an image-processing endpoint targeting CVE-2026-32882.
Detects high-volume POST requests containing HEIF, HEIC, or AVIF image content types, indicative of automated fuzzing or exploitation attempts against an image-processing endpoint targeting CVE-2026-32882.
This rule detects malformed SCTP packets that trigger a protocol decoding error ('pkt_too_small'). This behavior is associated with the 'DiagSpill' vulnerability (CVE-2026-74469), where specially crafted chunk sequences in the SCTP stream can cause a remote service crash or potential instability. The rule includes a threshold to mitigate noise from non-malicious malformed packets.
This rule detects malformed SCTP packets that trigger a protocol decoding error ('pkt_too_small'). This behavior is associated with the 'DiagSpill' vulnerability (CVE-2026-74469), where specially crafted chunk sequences in the SCTP stream can cause a remote service crash or potential instability. The rule includes a threshold to mitigate noise from non-malicious malformed packets.
Detects high-frequency SCTP ASCONF/ADD-IP chunk packets originating from external networks. This behavior is indicative of a Denial-of-Service (DoS) exploit attempt targeting a vulnerability (CVE-2026-74469) related to DiagSpill transport_count integer wraparound.
This rule detects malformed SCTP packets that trigger a protocol decoding error ('pkt_too_small'). This behavior is associated with the 'DiagSpill' vulnerability (CVE-2026-74469), where specially crafted chunk sequences in the SCTP stream can cause a remote service crash or potential instability. The rule includes a threshold to mitigate noise from non-malicious malformed packets.
Detects a specifically malformed IPv6 Routing Header (type 0) with a 'segments_left' value of 255 preceding an Authentication Header (AH). This signature targets an exploit pattern known as 'DirtyAH6', which aims to trigger a remote kernel crash or potential remote code execution on vulnerable systems by manipulating IPv6 header processing.
Detects a specifically malformed IPv6 Routing Header (type 0) with a 'segments_left' value of 255 preceding an Authentication Header (AH). This signature targets an exploit pattern known as 'DirtyAH6', which aims to trigger a remote kernel crash or potential remote code execution on vulnerable systems by manipulating IPv6 header processing.
Detects a specifically malformed IPv6 Routing Header (type 0) with a 'segments_left' value of 255 preceding an Authentication Header (AH). This signature targets an exploit pattern known as 'DirtyAH6', which aims to trigger a remote kernel crash or potential remote code execution on vulnerable systems by manipulating IPv6 header processing.
Detects high-frequency SCTP ASCONF/ADD-IP chunk packets originating from external networks. This behavior is indicative of a Denial-of-Service (DoS) exploit attempt targeting a vulnerability (CVE-2026-74469) related to DiagSpill transport_count integer wraparound.
Detects high-frequency SCTP ASCONF/ADD-IP chunk packets originating from external networks. This behavior is indicative of a Denial-of-Service (DoS) exploit attempt targeting a vulnerability (CVE-2026-74469) related to DiagSpill transport_count integer wraparound.
Detects high-frequency SCTP ASCONF/ADD-IP chunk packets originating from external networks. This behavior is indicative of a Denial-of-Service (DoS) exploit attempt targeting a vulnerability (CVE-2026-74469) related to DiagSpill transport_count integer wraparound.


