Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of Windows Installer (.msi) files or screensaver (.scr) files that were recently downloaded and executed via a web browser. Attackers often use these file types as lures for fake updates or software installers to execute malicious code on the victim's system.
Detects instances where cmd.exe or powershell.exe are launched from explorer.exe with command-line arguments containing DocuSign-themed keywords. This behavior is indicative of a 'ClickFix' phishing attack, where a user is socially engineered to copy and execute a malicious command via the terminal after interacting with a fraudulent DocuSign lookalike page.
Detects the silent installation or execution of Remote Monitoring and Management (RMM) tools when launched by script hosts (wscript.exe, mshta.exe, powershell.exe) which themselves were spawned by browser processes or explorer.exe. This pattern is characteristic of social engineering delivery chains, such as 'ClickFix', where a user is tricked into executing a script that subsequently fetches and runs RMM payloads for persistent remote access.
Detects behavior indicative of the MLTBackdoor malware, specifically the creation or modification of a DLL file (such as *dlp.dll) shortly after or before the creation of an RC4-encrypted 'data.bin' file on the same host. The rule also looks for an optional preceding archive extraction event of common file types from Temp or Downloads directories by standard extraction utilities, which may indicate the staging of the initial payload.
Detects the execution of 'filemanager.exe' and its subsequent access to sensitive browser credential stores (e.g., 'Login Data', 'cookies.sqlite'), occurring within a short window following a PowerShell-based ClickFix-style attack chain. The rule correlates initial suspicious script execution (often involving hidden windows, obfuscated commands, or web requests) with follow-on credential harvesting behavior on the same host.
Detects mshta.exe initiating outbound network connections, followed closely by the execution of a powershell.exe process with an unusually large command line, or PowerShell script block events containing large, potentially obfuscated scripts. This behavior is indicative of 'DeepLoad' or 'ClickFix' style staging, where legitimate binaries are leveraged to download and execute heavily obfuscated payloads.
Detects potential credential theft or malicious browser extension installation (DeepLoad-style) by monitoring for browser extension manifest file drops or registry-based extension force-installs occurring shortly after suspicious PowerShell command execution (ClickFix-style) on the same device.
Detects a sequence of activity where an endpoint performs multiple anti-analysis or sandbox evasion checks (using commands like wmic, powershell, or reg to query system information or look for debugger/VM artifacts) followed within 10 minutes by an outbound network connection to a domain that has not been observed from that specific device in the last 7 days.
Detects ClickFix-style fileless execution patterns where PowerShell pipelines (Invoke-RestMethod/Invoke-WebRequest) directly into execution cmdlets (Invoke-Expression/IEX) to download and execute remote scripts entirely in memory. The rule monitors for common bypass flags, hidden windows, and connections to suspicious IP address patterns or non-standard ports typically associated with malicious C2 staging.
This rule detects a multi-stage attack pattern involving potential social engineering via lookalike conferencing domains. It identifies users visiting suspicious domains resembling well-known conferencing platforms (e.g., Teams, Meet, Zoom), followed by modifications to the Windows RunMRU registry key and subsequent execution of suspicious commands (PowerShell, CMD, mshta) by explorer.exe within a short timeframe.
Detects potential supply chain attacks where a common external script (e.g., a widget) is loaded across multiple unrelated domains, followed by correlation with suspicious user-executed commands indicative of 'ClickFix' tactics (copying and pasting malicious code from a browser-based overlay into the Windows Run dialog).
Detects a potential ClickFix delivery attack where a user navigates to an automotive-themed website, interacts with the system via the Windows Run dialog (RunMRU), and subsequently executes command-line interpreters (powershell, cmd, wscript, mshta) spawned by explorer.exe within a short time window.
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
The following analytic identifies user accounts experiencing more than 5 account lockouts within a 5-minute time window.
It leverages the 'Change' data model and groups account lockout events into 5-minute time buckets to identify a high frequency of lockouts associated with the same user and destination.
This activity may indicate password spraying, brute-force activity, or repeated authentication attempts using invalid or outdated credentials.
If confirmed malicious, this behavior may indicate an attempt to gain unauthorized access to user accounts and could precede further compromise or lateral movement within the environment.
It leverages the 'Change' data model and groups account lockout events into 5-minute time buckets to identify a high frequency of lockouts associated with the same user and destination.
This activity may indicate password spraying, brute-force activity, or repeated authentication attempts using invalid or outdated credentials.
If confirmed malicious, this behavior may indicate an attempt to gain unauthorized access to user accounts and could precede further compromise or lateral movement within the environment.
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
Detects a behavioral fingerprint associated with the NeedyMantis group, characterized by the creation of a DLL and a identically-named, extensionless, encrypted archive file in the same directory within a short time window. This approach identifies the underlying packaging strategy rather than relying on static file names or known paths.
Page 133 of 1870


