Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects a multi-stage phishing attack sequence: it correlates the receipt of an invoice-themed email containing an anonymous SharePoint link with the subsequent local creation of a Windows Internet Shortcut (.url) file, followed by a Microsoft OAuth device-code authentication sign-in attempt by the user within a short timeframe. This behavior is indicative of an adversary tricking a user into downloading a malicious shortcut that facilitates OAuth device code phishing.
Detects web proxy requests that resemble phishing attempts targeting Apple Activation Lock. The rule identifies URLs containing specific Apple-related keywords in combination with common phishing URL paths, while filtering out legitimate Apple support documentation pages.
Detects the presence of the i-Realm companion tool associated with the AnonyMousKIT PhaaS platform, which is designed to bypass iOS Activation Lock features.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
Detects the execution of shell interpreters (PowerShell, CMD, Bash, Zsh) with suspicious command-line arguments typically associated with malicious activity, such as encoded commands, hidden window styles, or network download requests, when initiated by common user-facing applications like web browsers or Windows Explorer.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
Detects a suspicious sequence of events where msiexec.exe is launched by explorer.exe, subsequently spawning a suspended chrome.exe process. This is followed by the creation of a 'PavokwiLoader.exe' file in a 'Temp\modules' directory and the establishment of persistence by setting the 'Load' value within the 'HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows' registry key to execute the dropped loader.
This rule detects a suspicious process execution chain where a Chrome browser process launches cmd.exe, which subsequently spawns a setup executable (setup.exe or setup.tmp), leading to the execution of 7za.exe or a Python script/artifact. This pattern is indicative of a multi-stage malware execution chain, often involving the extraction or execution of payloads dropped via web-based sources.
Detects a suspicious execution chain where a command shell (cmd.exe) launched by explorer.exe uses curl.exe to download an MSI file from Azure Blob Storage, followed immediately by the installation of that MSI using msiexec.exe. This pattern is indicative of common malware delivery techniques, such as those observed with the RVTools.lnk delivery chain.
Detects a sequence of activity indicative of beacon-like behavior: initial domain reconnaissance using commands such as 'net', 'systeminfo', or 'nltest', followed by the execution of 'rundll32.exe' without command-line arguments, and subsequent LDAP (port 389) communication to a domain controller, all occurring within a short timeframe.
Detects instances where browser processes (Chrome or Edge) are spawned by smartscreen.exe and subsequently access sensitive browser storage files such as Login Data, Cookies, or Local State. This pattern is indicative of a process injection or masquerading chain used to extract credentials or session data.
Detects potential lateral movement or pivot attempts by correlating repeated failed RDP logons (RemoteInteractive) against sensitive targets (Domain Controllers, File Servers, Backup Servers) with concurrent security tool blocks (e.g., Microsoft Defender Antivirus, Exploit Guard) on the originating beachhead device within a 4-hour window.
Detects the execution of PowerShell with command-line arguments that suggest programmatically capturing or redirecting console output using ScriptBlock techniques (Create, Console, In, ReadToEnd). This pattern is often associated with obfuscated script execution, in-memory payloads, or attempts to bypass logging by capturing output via .NET streams.
Detects instances where Python interpreters (python.exe or pythonw.exe) are executed from a subdirectory within ProgramData that matches a 32-hex character pattern, initiated by the 7zip archive utility (7za.exe). This pattern is indicative of a self-extracting archive or malicious installer unpacking and executing Python scripts in a stealthy, non-standard location.
This rule detects a malicious execution chain starting with an MSI file being launched by explorer.exe from user-downloaded folders. The installer spawns chrome.exe, drops a specific loader file (e.g., PavokwiLoader.exe or Loader.exe) into the %LOCALAPPDATA%\Temp\modules\ directory, and establishes persistence via the HKCU 'Load' registry value pointing to that location.
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
Page 123 of 1870


