Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
This rule detects the presence of files matching known SHA256 hashes associated with the GhostCode phishing kit. It monitors for these files both in email attachments and on local device filesystems to identify potential delivery and execution of malicious phishing payloads.
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
Detects potentially malicious script execution chains where a user launches a JavaScript file (.js/.jse) from commonly abused directories (Downloads, Documents, Desktop, AppData, WinRAR temporary folders) via wscript.exe, which subsequently spawns PowerShell and establishes an external network connection within a short time window. This behavior is commonly associated with malware loaders, phishing attachments, and initial access payloads.
Detects the presence of a specific Russian-language error string ("Не удалось сгенерировать HWID") within binary files, which is characteristic of the HWID generation mechanism used by Vidar Stealer malware.
Detects the spawning of command-line interfaces such as cmd.exe, powershell.exe, or pwsh.exe as child processes of the SharePoint web application worker process (w3wp.exe). This behavior is highly irregular for a web server process and is indicative of potential exploitation, such as remote code execution (RCE) via web application vulnerabilities.
This rule detects malicious deserialization attempts targeting Microsoft SharePoint, specifically leveraging System.Data.Services.Internal.ExpandedWrapper combined with LosFormatter and System.Xaml.XamlServices. This signature is indicative of exploitation attempts related to CVE-2026-65660, allowing an attacker to achieve remote code execution by bypassing SafeControls restrictions.
Detects potential malicious PowerShell activity involving suspicious file paths in 'C:\Users\Public\' and the use of 'UPLOAD' command strings, which may indicate the staging and execution of payloads.
Detects network connections from workstation subnets to domain controllers using administrative protocols such as SMB (445), RPC (135), RDP (3389), or WinRM (5985/5986). This activity is indicative of lateral movement attempts by an adversary attempting to reach critical infrastructure from a compromised workstation in a flat or poorly segmented environment.
Detects an exploitation attempt against the SharePoint WebPartPagesWebService using the GetWebPartPageConnectionInfo method. The rule monitors for suspicious input patterns such as 'Register' and 'ignoreParentFrozen' within the URI query, which are indicative of a directive injection vulnerability.
Detects an attempt to exploit a quote-injection vulnerability within the SharePoint ToolPane.aspx page, specifically targeting the Register directive to bypass SafeControls restrictions. This pattern is commonly used for remote code execution or unauthorized application behavior modifications by manipulating server-side parsing.
Detects the presence of specific ysoserial gadget chain strings (ActivitySurrogateSelector/ActivitySurrogateDisableTypeCheck) indicative of deserialization attacks targeting Microsoft SharePoint via System.Web.UI.LosFormatter. This typically occurs in memory within w3wp.exe processes following an initial RCE exploit, such as those targeting EditingPageParser or ToolPane.
Page 153 of 1871



