Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
Detects the use of reg.exe to query the MachineGuid value from the Windows Registry (HKLM\SOFTWARE\Microsoft\Cryptography). This behavior is often associated with adversary reconnaissance, specifically host fingerprinting, to uniquely identify compromised machines.
Detects unauthorized or non-standard processes attempting to access sensitive browser cookie storage files, which is a common technique used by credential-stealing malware to exfiltrate session data and bypass multi-factor authentication.
Detects the use of 7-Zip (7z.exe) to extract a file named drata.dat using command line arguments that indicate silent extraction from an encrypted or password-protected archive. This behavior is associated with the LegionLoader malware, which uses this technique to stage its payload.
This rule detects suspicious PowerShell activity associated with the Lightlife RAT, specifically targeting Google Chrome's login data files to steal credentials and performing checks for the presence of cryptocurrency wallets.
Detects potential path traversal or unauthorized access attempts by Semantic Kernel Agents (or related processes like Python/DotNet) to sensitive host files. The rule monitors for file read, creation, or modification activities targeting sensitive credentials, configuration files (e.g., .ssh, .aws, .kube), and system files, which could indicate a sandbox escape or malicious data collection.
Detects exploit attempts targeting a Python prompt-injection vulnerability (CVE-2026-26030). The rule identifies command lines attempting to traverse Python's object hierarchy (e.g., using __class__, __base__, __subclasses__) to import the os module and execute system commands. It also flags subsequent child processes (e.g., calc.exe, cmd.exe) spawned by Python interpreters or Semantic Kernel host processes.
This rule detects the creation of potentially malicious script or executable files (.bat, .ps1, .exe, .vbs) within the Windows Startup folder. It triggers when these files are created by processes typically used for automation or development (dotnet, python) or processes utilizing specific semantic/download-related command lines. The rule further correlates this activity with the presence of PowerShell commands indicative of script downloading or code execution (e.g., IEX, DownloadString) by the same device within the same timeframe, suggesting persistent execution of potentially malicious code.
This rule identifies non-browser processes (and those not originating from standard installation directories of common browsers) that exhibit persistent, repeated network connections to the OpenAI API. This pattern is indicative of potential C2 traffic, where adversaries abuse the OpenAI Assistants API as a covert communication channel (e.g., SesameOp).
Detects outbound HTTP GET requests containing a .ps1 file extension in the URI, originating from a host without a specified User-Agent, and targeting domains other than Microsoft or Windows Update. This pattern is characteristic of a persistence mechanism executing a PowerShell script to download a secondary payload (e.g., via Net.WebClient).
Detects instances where browser automation tools (e.g., Selenium, Puppeteer, Playwright) or headless browser instances initiate command-line interpreters or scripting hosts. This behavior is indicative of potential automated exploitation, such as browser-based attacks where a malicious script attempts to execute commands directly on the host operating system.
This rule detects scenarios where a browser or agent process downloads a file and subsequently initiates a local process that references the downloaded file within a very short timeframe (2 minutes). This pattern is indicative of automated or agentic behavior (such as AI-assisted malware execution) where a download is followed by immediate, non-human-mediated execution of the downloaded content.
This rule detects potential AI agent prompt injection by monitoring email subjects or attachment names for keywords often associated with system instruction overrides. It correlates these potentially malicious emails with subsequent execution of common administrative or script-interpreting binaries (e.g., PowerShell, cmd.exe) on the recipient's device within a one-hour window, suggesting a potential successful hijack of an automated process or AI agent.
Detects unauthorized processes (non-browser) reading sensitive browser session and credential files (e.g., Cookies, Login Data) across multiple user profiles, followed by immediate outbound network connections. This behavior is highly characteristic of commodity information stealers (e.g., LummaC2, Stealc, Vidar) attempting to exfiltrate browser-stored credentials and session data.
This rule detects outbound HTTP GET requests initiated by a process using a 'WebClient' user-agent to retrieve a file named 'shell.ps1'. This behavior is characteristic of adversaries downloading second-stage PowerShell payloads to a compromised host.
Detects instances where an AI agent (e.g., Semantic Kernel) launches command-line tools commonly used to perform bulk data destruction or system wiping, such as file deletion commands, volume shadow copy removal, or disk formatting. This rule flags suspicious orchestration by AI agents that may be acting outside of expected parameters.
Detects the creation or modification of documents in common formats (e.g., .txt, .md, .docx, .pdf) that contain strings indicative of prompt-injection attempts. These strings are commonly used to manipulate the behavior of AI agents or Large Language Models (LLMs) that may process or index these files automatically.
Detects the installation of a Windows service where the ImagePath points to a gitlab-runner executable but the ServiceName deviates from the default 'gitlab-runner' name. This technique is often used to mask persistence or evade simple naming-based detections by utilizing the --service flag to rename the runner service.
Detects execution of the BTR_CLI.exe utility with specific command-line arguments. The flags monitored include -a, -chain, -item, -trigger, and -cleanup, which suggest administrative, chaining, or automated triggering behaviors of a custom or proprietary command-line interface tool. This rule tracks the command-line usage to identify potential automated task execution or system configuration changes.
Detects the execution of BTR_CLI.exe with cleanup parameters that correlate with the deletion of specific registry keys (services) and related file artifacts (e.g., .dat or changelist files) within a short time window. This pattern is indicative of a post-compromise cleanup routine aimed at removing traces of malicious services or payloads.
Detects the execution of BTR_CLI.exe with command line arguments indicative of installing or interacting with the Mimikatz driver (mimidrv.sys). This behavior is associated with loading the malicious driver to facilitate credential dumping from kernel memory.
Page 149 of 1871

