Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where explorer.exe (the Windows Shell) spawns a PowerShell process with suspicious flags, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands into the Windows Run dialog.
Detects the Graphalgo Go-based remote access trojan (RAT) sending an initial system report containing device and user information to the Slack API. This activity occurs during the initial check-in phase before establishing a primary command and control channel.
Detects high-risk destructive database operations (DROP, TRUNCATE, or UPDATE) on sensitive tables executed within six hours of a large outbound data transfer from the same host, a pattern indicative of anti-forensic database wiping following data exfiltration.
Detects the 'ClickFix' technique where a user is socially engineered into copying a malicious command to their clipboard and pasting it into the Windows Run dialog (Win+R). The rule monitors for powershell.exe spawned by explorer.exe containing specific social engineering keywords or typical fileless download-execute patterns like 'irm', 'iex', or 'Invoke-RestMethod'.
This rule detects potential Pass-the-Hash lateral movement by identifying NTLM network logons (Event ID 4624, LogonType 3) on a host that lack a preceding interactive (LogonType 2, 10) or Kerberos-authenticated logon, coupled with subsequent access to sensitive administrative shares (Event ID 5140) by the same user account.
This rule detects potential credential dumping from the Local Security Authority Subsystem Service (LSASS) memory. It identifies two common techniques: 1) The use of the Windows 'comsvcs.dll' library exported via 'rundll32.exe' to initiate a minidump of the LSASS process, and 2) Unauthorized processes opening handles to LSASS with specific access rights (0x1010, 0x1410) often associated with memory reading for dumping purposes.
Detects techniques associated with LSASS process credential dumping, including direct handle access to the LSASS process with specific access masks (common in tools like Mimikatz), the use of rundll32.exe to invoke comsvcs.dll for memory dumping, and the creation of LSASS dump files on disk.
Detects execution of PowerShell processes employing common obfuscation and evasion techniques frequently associated with fileless malware loaders and malicious script execution. This includes the use of EncodedCommand, Base64 strings, IEX/Invoke-Expression download cradles, and stealth execution flags (e.g., hidden windows combined with non-interactive modes).
Detects anomalous lateral movement behavior where a single user account authenticates via NTLM to three or more distinct target hosts within a short time window (10 minutes). This pattern of rapid, broad authentication is a strong indicator of a Pass-the-Hash (PtH) attack.
Detects unauthorized directory service access requests (Event ID 4662) utilizing the 'DS-Replication-Get-Changes' or 'DS-Replication-Get-Changes-All' extended rights GUIDs. These rights are required for the DCSync technique used by tools like Mimikatz or Impacket to replicate Active Directory data. The rule specifically flags when such requests originate from a non-domain controller host, which is a strong indicator of credential theft or unauthorized replication attempts.
This rule detects potential lateral movement via WMI by identifying two distinct suspicious behaviors: WmiPrvSE.exe spawning unexpected child processes (excluding common legitimate processes) or the usage of wmic.exe and PowerShell cmdlets (Invoke-WmiMethod, Invoke-CimMethod) to execute processes on remote systems, as indicated by command line arguments specifying target nodes or computer names.
Detects suspicious PowerShell execution patterns involving encoded commands, hidden window styles, or common download cradles combined with code obfuscation techniques. This rule monitors PowerShell ScriptBlock Logging (Event ID 4104) for combinations of indicators often used by threat actors to evade detection, such as Base64-encoded strings, hidden execution flags, network download utilities, and script obfuscation techniques.
Detects the assignment of special, highly privileged rights (e.g., SeDebugPrivilege, SeImpersonatePrivilege) to standard user accounts using Windows Security Event ID 4672. This activity, without an associated new logon event, is a common indicator of access token manipulation or impersonation techniques (such as those used by tools like Incognito) to gain elevated system privileges.
Detects unauthorized or suspicious use of Windows Management Instrumentation (WMI) for lateral movement and remote code execution. The rule monitors for common WMI exploitation vectors, including the use of wmic.exe for process creation, PowerShell or C# invocations of WMI/CIM methods (such as Win32_Process Create), WMI event subscription registration for persistence, and the execution of mofcomp.exe.
Detects the abuse of Windows signed binaries (LOLBins) rundll32.exe and regsvr32.exe for proxy execution. Rundll32.exe activity is monitored for the use of javascript: pseudo-protocol or comsvcs.dll for MiniDump operations, while regsvr32.exe activity is monitored for Squiblydoo-style remote scriptlet execution via /i:http and other suspicious flag combinations.
This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys where the configured value points to a file located in common user-writable or temporary directories (AppData, Temp, ProgramData) with an executable extension (.exe, .dll, .scr, .bat, .vbs, .ps1, .cmd). This pattern is a common technique used by adversaries to establish persistence by ensuring malicious code executes automatically upon user login or system startup.
This rule detects potential DNS tunneling activity by identifying DNS requests with suspicious characteristics, such as the use of TXT/NULL query types, high-entropy subdomains, or oversized queries. It further aggregates these suspicious requests per parent domain and flags scenarios where a high volume of requests or unique subdomains are observed, indicating possible data exfiltration or C2 communication.
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
KQL Query from file: Network detection - C2 domains and static key
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
Page 128 of 1870

