Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects the clearing of the Windows Security event log, which generates Event ID 1102. This action is often performed by adversaries to cover their tracks after performing malicious activities on a compromised host.
Detects anomalous SOAP requests to the SharePoint WebPartPages.asmx endpoint specifically targeting the 'GetWebPartPageConnectionInfo' method. This pattern is associated with exploitation attempts against SharePoint vulnerabilities.
Detects the installation and execution of MeshAgent, a remote monitoring and management (RMM) tool, by identifying specific command-line arguments, service names, and renamed binary execution. Adversaries often use RMM tools for persistent remote access and command and control.
This rule monitors network connections initiated by common web browsers (chrome.exe, msedge.exe, brave.exe) to known domains associated with a specific VPN proxy service or subscription-based proxy farm infrastructure. The rule flags endpoints communicating with URLs involved in proxy beaconing, fallback hosting, and subscription API calls.
Detects instances where the Microsoft Edge proxy process (msedge_proxy.exe) initiates command-line interpreters such as cmd.exe, powershell.exe, or pwsh.exe. This behavior is highly suspicious as a browser-related process should not typically be spawning shell interpreters, potentially indicating exploitation of browser vulnerabilities or malicious script execution.
Detects anomalous process execution (cmd.exe, powershell.exe, wmic.exe, tasklist.exe, taskkill.exe) initiated by the process 'ReportDump.exe'. This activity is indicative of the SectopRAT payload performing remote shell, file management, or process control tasks initiated via a C2 channel.
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
Detects suspicious process-injection related API calls (such as CreateRemoteThread, VirtualAllocEx, and WriteProcessMemory) where the source or target process is a common AI agent runtime environment (e.g., python.exe, node.exe, java.exe, dotnet.exe). This detects potential malicious code execution or reflective loading initiated by or targeting these runtime processes.
Detects when an AI agent's code execution sandbox (e.g., Python, Node.js, or Shell interpreters) initiates suspicious child processes. This includes the execution of network utilities for potential C2 (e.g., curl, nc, socat), the creation of interactive reverse shells, or the execution of credential harvesting tools (e.g., mimikatz, secretsdump), which suggests the AI agent's sandbox environment has been compromised or abused.
Detects the abuse of the CMSTPLUA COM object, a known technique for UAC bypass, to execute a hidden and non-profile PowerShell process. This behavior is associated with malicious activity chains like RemotePanel or BoundSiphon that aim to achieve elevated execution.
Detects instances where the SQL Server process (sqlservr.exe) initiates command-line utilities such as cmd.exe or powershell.exe, and further identifies suspicious command-line arguments often associated with post-exploitation activity like discovery, credential gathering, or file manipulation.
This rule detects a potential brute force attack against the Microsoft SQL Server 'sa' administrative account. It identifies a high volume of failed authentication events (Event ID 18456) for the 'sa' account within a 10-minute window, followed by a successful authentication event (Event ID 18453 or 18454) from the same source IP address. The rule specifically filters for successful logins originating from non-private (internet-facing) IP addresses, suggesting an attempt from an external threat actor.
Detects a sequence of events where a suspected sideloaded process (e.g., masquerading as common tools like curl or vim) is followed within 30 minutes by the registration of a new Windows service, a behavioral pattern associated with the NeedyMantis threat group.
Detects a suspicious sequence of events characteristic of NeedyMantis's hands-on-keyboard activity. The rule identifies file staging (creation or modification of suspicious DLLs from network shares) followed by remote command execution (via Impacket-like service interaction) and subsequent execution of binaries vulnerable to DLL sideloading.
This rule monitors for sustained, repeated network connections from specific processes (often legitimate binaries used by the NeedyMantis group for loader activities) to known NeedyMantis-associated C2 domains. It triggers when an initiating process, associated with known loader activity, maintains a persistent communication pattern consistent with an active WebSocket C2 session.
Detects the execution of the encryptbase64.ps1 PowerShell script when invoked by a process other than PowerShell or PowerShell Core. This behavior is indicative of NeedyMantis malware attempting to evade detection by executing scripts outside standard script hosts.
Detects suspicious command execution patterns involving cmd.exe or powershell.exe spawned by services.exe, or involving redirection to temporary files, which are consistent with Impacket-based remote service execution commonly associated with NeedyMantis malware deployment.
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
Page 14 of 1866


