Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
Detects attempts to disable Windows Defender by either executing known Defender Control utilities or by modifying registry keys associated with the disabling of anti-spyware features or the WinDefend service startup.
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
Detects the clearing of Windows Security Event Logs (EventID 1102) within 15 minutes of a successful user logon (EventID 4624) on the same host. This activity is a common anti-forensics technique used by adversaries to hide malicious actions following an authenticated session.
Detects the stopping or modification of critical security and backup services on Windows endpoints. This behavior often indicates an attempt by an adversary to impair defensive capabilities or disable logging to facilitate malicious activity.
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
This rule detects attempts to exploit the Microsoft Support Diagnostic Tool (MSDT) vulnerability CVE-2022-30190, known as 'Follina'. The rules monitor for malicious HTTP traffic and payloads that leverage the 'ms-msdt' URI scheme to execute arbitrary commands, often delivered via weaponized documents or external references to remote malicious HTML files.
Detects network traffic patterns characteristic of the EternalBlue (MS17-010) exploit targeting the SMBv1 protocol. Specifically, it monitors for a malformed SESSION_SETUP request containing an unusually large payload, which is indicative of an attempt to trigger a buffer overflow in the SMB service.
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
Detects sequential suspicious SMB activity characteristic of PsExec lateral movement: connection to ADMIN$ or C$ administrative shares, followed by the upload of an executable or batch file to the share, and subsequently the usage of SVCCTL (CreateServiceW/StartServiceW) to execute the uploaded binary.
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
Detects an Active Directory Certificate Services (AD CS) Certificate Enrollment Service (CES) SOAP request that includes a 'CertificateTemplate' item in the 'AdditionalContext' body, potentially indicating a directed attempt to request a specific certificate template during enrollment.
This rule detects potential NTLM relay or authentication downgrade attempts by monitoring HTTP POST requests to the Certificate Enrollment Service (CES) endpoint. It specifically flags when an 'Authorization' header contains an NTLM-wrapped 'Negotiate' token, which is often indicative of an attacker attempting to coerce or relay authentication material to the service.
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
The following analytic identifies instances where CrushFTP has blocked access due to exceeding the maximum number of simultaneous connections from a single IP address. This activity may indicate brute force attempts, credential stuffing, or automated attacks against the CrushFTP server. This detection is particularly relevant following the discovery of CVE-2025-31161, an authentication bypass vulnerability in CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.
The following analytic detects Log4Shell JNDI payload injections via outbound connections. It identifies suspicious LDAP lookup functions in web logs, such as `${jndi:ldap://PAYLOAD_INJECTED}`, and correlates them with network traffic to known malicious IP addresses. This detection leverages the Web and Network_Traffic data models in Splunk. Monitoring this activity is crucial as it targets vulnerabilities in Java web applications using log4j, potentially leading to remote code execution. If confirmed malicious, attackers could gain unauthorized access, execute arbitrary code, and compromise sensitive data within the affected environment.
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
Page 116 of 1870

