Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the installation of machine learning or AI software dependencies (pip, conda, npm, poetry) that either pull from unauthorized registries or match known malicious/typosquatting naming patterns (e.g., LiteLLM supply-chain compromise). The rule also monitors for newly published packages that have been flagged as suspicious.
Detects an AI agent session that performs a data exfiltration action (e.g., sending an email, webhook, or file share) to an unauthorized or non-allowlisted destination shortly after the agent has ingested potentially untrusted external content. This behavior is indicative of an AI agent being manipulated to exfiltrate data after processing malicious or adversarial inputs.
This rule monitors package installation logs for indicators of packages potentially generated or suggested by AI tools (e.g., Copilot, code assistants) being installed in a target environment. It specifically looks for a low volume of installations (<=3) for packages that have been published within the last 14 days, which is a pattern often associated with the 'Publish Hallucinated Entities' technique in AI systems, where malicious or hallucinated code packages are introduced into the supply chain.
This rule detects the execution of common Windows administration utilities (vssadmin.exe, wmic.exe, wbadmin.exe, bcdedit.exe) being used to delete Volume Shadow Copies, backup catalogs, or modify boot configuration data to disable automatic recovery. These actions are frequently performed by ransomware to prevent data restoration.
Detects instances where Microsoft Office applications or Windows Explorer (via LNK file execution) spawn suspicious child processes, such as script interpreters or known LOLBins, within a short timeframe. This is a common pattern for initial access via spearphishing attachments where a malicious document or shortcut executes a payload.
Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
Detects high-volume file rename and modification operations occurring across multiple directories, combined with the creation of files indicative of ransom notes (e.g., readme, decrypt, how-to-restore). This pattern is strongly associated with the encryption phase of a ransomware attack.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell cmdlets that execute with SYSTEM privileges, or tasks that reference common temporary directories or persistence triggers (logon, idle). This behavior is frequently associated with ransomware, malware persistence, or staged payload execution.
Detects the execution of PowerShell with encoded command arguments (e.g., -enc, -EncodedCommand) combined with common web-request cmdlets or download-cradle patterns (e.g., IEX, Net.WebClient, Invoke-WebRequest). This pattern is frequently used by adversaries to execute obfuscated remote payloads in memory.
Detects a suspicious burst of commands commonly used to disable security services, antivirus, or backup agents on a single host. The rule monitors for a high frequency of taskkill, net stop, sc stop, or PowerShell Stop-Service operations targeting a predefined list of sensitive security software process and service names within a short timeframe, which is a common precursor to ransomware encryption.
Detects attempts by an adversary to disable or clear Windows Event logs using standard administrative utilities such as wevtutil, PowerShell, auditpol, net, sc, or wmic to cover tracks or hinder forensic analysis.
Detects persistence attempts via Windows Registry run keys and Startup folders. The rule identifies suspicious modifications to run/runonce registry keys involving common user-writable paths (e.g., Temp, AppData) or the execution of PowerShell commands with common obfuscation flags (e.g., -enc). Additionally, it detects the creation of executable files (.lnk, .ps1, .vbs, .bat) within user Startup folders.
Detects persistence attempts via Windows Registry run keys and Startup folders. The rule identifies suspicious modifications to run/runonce registry keys involving common user-writable paths (e.g., Temp, AppData) or the execution of PowerShell commands with common obfuscation flags (e.g., -enc). Additionally, it detects the creation of executable files (.lnk, .ps1, .vbs, .bat) within user Startup folders.
This rule detects the deployment of suspicious executables or scripts (e.g., .exe, .bat, .ps1, .vbs) via Group Policy (GPO) paths or through GPO-related processes like gpscript.exe and gpupdate.exe. This activity is consistent with using GPOs to distribute and execute malicious binaries across a domain, often a precursor to ransomware deployment.
Detects the deletion of Windows Volume Shadow Copies using vssadmin.exe, wmic.exe, or PowerShell (WMI/CIM objects). This activity is commonly used by ransomware to prevent local data recovery by destroying shadow copy backups before encryption.
Detects the deletion of Windows Volume Shadow Copies using vssadmin.exe, wmic.exe, or PowerShell (WMI/CIM objects). This activity is commonly used by ransomware to prevent local data recovery by destroying shadow copy backups before encryption.
Detects attempts to clear Windows Event Logs using either the native 'wevtutil.exe' utility or PowerShell cmdlets 'Clear-EventLog' and 'Remove-EventLog'. Adversaries often perform this action to remove evidence of their presence or malicious activities from a compromised system.
Detects the use of command-line tools like s5cmd or aws-cli to synchronize or copy data to an Amazon S3 bucket. The rule identifies suspicious patterns by looking for specific transfer commands combined with recursive or high-concurrency flags that indicate mass data movement often associated with exfiltration.
Detects unauthorized attempts to access sensitive Veeam Backup and Replication credentials by querying the backend SQL database or directly accessing DPAPI Master Key files. This activity is indicative of an attacker attempting to decrypt backup credentials stored by the Veeam service.
Detects the creation of scheduled tasks using 'schtasks.exe' or 'Register-ScheduledTask' where the task command path is located in suspicious directories such as AppData, Temp, or ProgramData, or where the task is configured to run under the SYSTEM account. This behavior is commonly used by adversaries for persistence.
Page 106 of 1870
