Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects instances where PowerShell processes initiate outbound WebDAV connections, potentially to download or stage malicious DLLs. The detection rule correlates network activity involving WebDAV indicators (e.g., DavWWWRoot) with subsequent local file creation events for DLL files within WebDAV-related folders.
Detects the use of 'terraform init' where the command line arguments reference known typosquatted HashiCorp registry domains. This behavior is indicative of a supply chain attack attempting to pull malicious providers or modules from an adversary-controlled source.
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
This rule monitors network, DNS, and HTTP activity to identify connections to known infrastructure associated with the ClickFix social engineering campaign and Vidar infostealer malware. The rule correlates device network events, HTTP request events, and DNS queries against a list of known malicious domains, IP addresses, and URL patterns used for C2, staging, and lures.
This rule detects potential unauthorized account creation by correlating suspicious administrative activity on network edge devices (VPNs, firewalls) with subsequent local administrator account creation on an internal host within a one-hour window. This behavior is indicative of ransomware affiliates exploiting internet-facing infrastructure to gain initial access and escalate privileges.
Detects multiple methods of tampering with Windows Defender security controls within a short time window. This includes PowerShell commands to modify Defender preferences (e.g., disabling Real-time Monitoring or adding exclusions), modifications to Defender-related registry keys, and attempts to stop or disable the WinDefend service.
Detects processes establishing persistence via Windows Registry 'Run' keys followed by frequent outbound network connections over non-standard ports. This behavior is consistent with the SystemBC/Coroxy SOCKS5 proxy backdoor often utilized by ransomware actors like Ryuk, Conti, BlackBasta, Play, and Rhysida.
Detects persistence mechanisms used by The Gentlemen ransomware, specifically the creation of malicious scheduled tasks (UpdateUser, UpdateSystem, or gentlemen_system) and modification of registry Run keys (GupdateS or GupdateU). The rule also monitors for the presence of the operator password string 'G7Vz9eyG' within command line arguments.
Detects attempts to terminate security-related processes (AV/EDR) using common administrative tools including taskkill.exe, wmic.exe, and PowerShell Stop-Process. This behavior is frequently observed during the pre-encryption phase of ransomware attacks, such as Nova and Gentlemen, to evade detection.
Detects ClickFix-style social engineering attacks where a user is tricked into manually executing a PowerShell command. The command typically utilizes Invoke-RestMethod to fetch a remote payload and Invoke-Expression to execute it in memory, bypassing execution policies. This behavior is commonly associated with campaigns like SmartApeSG and DeepLoad.
Detects the DeepLoad malware staging process injection by spawning trusted Windows binaries (LockAppHost.exe, makecab.exe, or Magnify.exe) in a suspended state from an unauthorized parent process. This behavior is indicative of an APC-based injection sequence where malicious code is written into the suspended process before execution.
Detects the execution of PowerShell scripts 'first.ps1' and 'main1.ps1', which are components of a known credential phishing toolset. This tool displays a fake Windows Update dialog to trick users into providing their credentials, which are then exfiltrated via SMB, DNS, or HTTP.
Detects reconnaissance and persistence behaviors associated with the Akira ransomware attack chain, specifically the execution of the Cloudflare Tunnel daemon for remote access or the creation/modification of local user accounts via standard Windows tools.
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
This rule detects modifications or creation of Git hooks ('pre-commit', 'post-checkout') within local repository directories. Attackers can leverage these hooks as an execution trigger for arbitrary code whenever standard Git actions occur, facilitating persistence or privilege escalation on compromised developer machines.
Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
Page 108 of 1870


