Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
Detects anomalous access to the SharePoint WebPartPages.asmx SOAP endpoint, specifically using the GetWebPartPageConnectionInfo method. This query identifies patterns consistent with the exploitation of CVE-2026-65660, where adversaries attempt to smuggle WebPart template markup (e.g., <%@ Register, XamlServices) after legitimate preview methods have been disabled.
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
This rule detects successful network connections to known malicious IP addresses or the domain 'forgitlab.com', which are associated with the Azazel malware threat infrastructure.
This rule detects successful network connections to known malicious IP addresses or the domain 'forgitlab.com', which are associated with the Azazel malware threat infrastructure.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools when initiated from suspicious parent processes (such as browsers, office applications, or command-line interpreters), originating from common writeable directories (e.g., Temp, Downloads), or executed with command-line arguments indicative of silent/unattended installation. This behavior is often associated with initial access, persistence establishment, or unauthorized remote control of a system.
Detects techniques commonly used to dump Active Directory domain credentials by accessing the NTDS.dit database file. This includes the use of ntdsutil for IFM (Install From Media) operations, manual shadow copy creation using vssadmin or wmic to copy the ntds.dit file, direct access to shadow copy volumes containing sensitive database files, and the use of credential dumping tools like Impacket's secretsdump.
Detects the abuse of the Windows built-in utility 'certutil.exe' to download files from remote locations using the 'urlcache', 'verify', or 'verifyctl' arguments. Attackers often leverage this LOLBIN to download malicious payloads as it is a trusted system binary.
The following analytic identifies a popular 3rd party software process being executed where it's process name does not match it's original file name attribute.
Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
Detects attempts to inhibit system recovery by deleting Volume Shadow Copies or modifying Windows Boot Configuration Data, a technique commonly employed by LockBit and other ransomware families prior to file encryption.
Detects msiexec.exe spawned from explorer.exe, consistent with a user double-clicking a malicious .lnk shortcut, where the command line triggers the installation of an MSI package hosted on a remote HTTP/HTTPS server. This behavior is a known initial access technique used by FIN7 to deliver malicious payloads.
Page 13 of 1866


