Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors network, DNS, and HTTP activity to identify connections to known infrastructure associated with the ClickFix social engineering campaign and Vidar infostealer malware. The rule correlates device network events, HTTP request events, and DNS queries against a list of known malicious domains, IP addresses, and URL patterns used for C2, staging, and lures.
This rule detects potential staging activity for ClickFix or Vidar malware campaigns. It identifies the creation of files or folders in directories mimicking Windows Diagnostics infrastructure (WDI) or known payload paths, correlated with the execution of suspicious PowerShell commands or archive-related utilities within a 30-minute window on the same device.
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
This rule detects malicious activity related to the exploitation of MpDlpService.exe. It looks for the execution or presence of known malicious file hashes associated with this threat, including a P-stage script, payload files, and a malicious mpclient.dll. Additionally, it identifies instances where the legitimate MpDlpService.exe binary is executed from a non-standard, suspicious directory, which is a common indicator of side-loading or persistence techniques.
This rule detects malicious activity related to the exploitation of MpDlpService.exe. It looks for the execution or presence of known malicious file hashes associated with this threat, including a P-stage script, payload files, and a malicious mpclient.dll. Additionally, it identifies instances where the legitimate MpDlpService.exe binary is executed from a non-standard, suspicious directory, which is a common indicator of side-loading or persistence techniques.
This rule monitors for two distinct suspicious patterns: first, the interaction between Claude Desktop and the CEF (Chromium Embedded Framework) library, which may indicate unauthorized plugin or extension loading; second, the execution of non-standard binaries initiated by various JetBrains IDE processes located outside of standard program directories, which could indicate process hollowing or unauthorized tool execution.
Detects web proxy requests that resemble phishing attempts targeting Apple Activation Lock. The rule identifies URLs containing specific Apple-related keywords in combination with common phishing URL paths, while filtering out legitimate Apple support documentation pages.
Detects the presence of the i-Realm companion tool associated with the AnonyMousKIT PhaaS platform, which is designed to bypass iOS Activation Lock features.
Detects artifacts associated with the JWR phishing framework client engine, specifically focusing on the presence of self-referential .toString().search() anti-debugging checks, decoy variable naming conventions, and WebSocket communication components (JWRCID/JWRCVV, ws-worker.js) used for session establishment.
Detects the presence of known AnonyMousKIT Phishing-as-a-Service (PhaaS) shared components (legacy.js, Core.js, ToolsController.php) by matching specific file hashes or detecting these filenames in small files. This rule is designed to identify backend infrastructure used by phishing resellers.
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
Detects HTML smuggling files identified as 'FlipBook' lures, commonly used in device-code phishing campaigns. These lures utilize client-side JavaScript for AES-GCM decryption, extensive comment-based obfuscation, and specific junk-padding techniques to bypass security controls and trick users into providing credentials.
This rule detects network activity associated with the GhostCode phishing kit. It monitors for sequential calls to the harvester backend (geoip, get_code, and poll) from specific suspicious hostnames, indicating a likely interaction between a victim and a credential harvesting landing page.
Page 155 of 1871


