Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution of PowerShell with hidden window styles and encoded commands, initiated with High Integrity (Admin) privileges. This pattern is often indicative of bypasses for User Account Control (UAC) or malicious script execution where an adversary attempts to run elevated code while minimizing user visibility.
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects modifications to Group Policy Objects (GPOs) or GPO links in Active Directory, specifically targeting known malicious GPO identifiers, GPO payloads, or changes to policy versioning and linking that indicate unauthorized configuration changes for persistence or privilege escalation.
Detects a cluster of Windows Event IDs 4740 (Account Lockout) or 4724 (Password Reset) targeting the local 'Administrator' account across multiple hosts within a short time window. This activity is indicative of automated or mass account manipulation often associated with ransomware payloads or centralized GPO-based credential tampering.
Detects a suspicious pattern across the environment where a large number of devices apply Group Policy Objects (GPO) shortly after rebooting. This behavior is indicative of potential unauthorized GPO modification used as a persistence or execution mechanism, where malicious logic is staged within a GPO to trigger across the domain upon machine startup.
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
Detects the execution of PowerShell via a shortcut (.lnk) file that attempts to download and execute remote content using 'Invoke-WebRequest'. The command lines use common obfuscation techniques like 'Hidden' window style and 'Bypass' execution policy, targeting specific known malicious URL patterns or filename keywords.
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
Detects the execution of PowerShell scripts located in Windows temporary directories (AppData/Local/Temp or Temp) that utilize common evasion flags such as hidden window style, bypass execution policy, or non-interactive mode. This behavior is frequently associated with initial stagers, droppers, or malicious script execution.
Detects the loading of specific DLL files (winfsp-x64.dll or DukeQt.dll) where the loading process or the DLL file location originates from outside the legitimate system directory (C:\Windows\). This behavior is often associated with DLL sideloading or search order hijacking where a malicious actor places a DLL in an untrusted directory to be loaded by a legitimate application.
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
Detects UNC6240 PSEMHUB.war web shell/tunnel/trojanized installer artifacts by distinctive content markers (x.jsp, u.jsp, tunnel.jsp/jspx, Ple64.exe)
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
Page 102 of 1870

