Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
30 detections
Filters
Last updated
All Time
Detection languages
30
Contributors
25
2
1
1
1
Categories
30
26
9
5
4
Platforms
30
4
2
Products / Services
30
28
1
1
MITRE Techniques
26
19
17
6
4
CVEs
12
4
4
4
1
IDS Classtypes
1,896
482
449
381
237
30
IDS Protocols
12
5
4
4
3
This rule detects malformed SCTP packets that trigger a protocol decoding error ('pkt_too_small'). This behavior is associated with the 'DiagSpill' vulnerability (CVE-2026-74469), where specially crafted chunk sequences in the SCTP stream can cause a remote service crash or potential instability. The rule includes a threshold to mitigate noise from non-malicious malformed packets.
This rule detects a high volume of SCTP traffic targeted at internal systems, characterized by mass endpoint creation. This behavior is indicative of an exploit attempt against the 'sctp_diag' kernel component (CVE-2026-74469), which can lead to an out-of-bounds (OOB) write condition, potentially resulting in system instability or denial of service.
This rule detects a high volume of SCTP traffic targeted at internal systems, characterized by mass endpoint creation. This behavior is indicative of an exploit attempt against the 'sctp_diag' kernel component (CVE-2026-74469), which can lead to an out-of-bounds (OOB) write condition, potentially resulting in system instability or denial of service.
This rule detects a high volume of SCTP traffic targeted at internal systems, characterized by mass endpoint creation. This behavior is indicative of an exploit attempt against the 'sctp_diag' kernel component (CVE-2026-74469), which can lead to an out-of-bounds (OOB) write condition, potentially resulting in system instability or denial of service.
This rule detects a high volume of SCTP traffic targeted at internal systems, characterized by mass endpoint creation. This behavior is indicative of an exploit attempt against the 'sctp_diag' kernel component (CVE-2026-74469), which can lead to an out-of-bounds (OOB) write condition, potentially resulting in system instability or denial of service.
This rule detects a high volume of TCP synchronization (SYN) packets from external sources directed at a Cisco IOS XR network device. This behavioral pattern is indicative of a resource exhaustion denial-of-service (DoS) attack, potentially attempting to exploit vulnerabilities such as CVE-2026-20274 by flooding the control plane.
Detects high-volume outbound SYN packet bursts from internal hosts to external networks, excluding known service ports. This behavior is indicative of a compromised host acting as part of a botnet conducting a SYN flood Denial of Service attack.
DOS Sustained ICMP Flood Attempt
Suricata
This rule detects a sustained ICMP flood attempt, which is a type of Denial of Service (DoS) attack. It triggers an alert if more than 100 ICMP packets (type 8, echo request) are observed from an external network to the home network within a 10-second window, tracked per source IP. This indicates an adversary is attempting to overwhelm the target system or network with ICMP traffic.
This rule detects a high rate of ICMP echo requests from a single source to a server within the home network, indicating a potential Denial of Service (DoS) attack. It triggers an alert if more than 50 ICMP echo requests are observed from the same source within a 1-second interval.


