Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects lateral movement activities associated with The Gentlemen ransomware group. The rule monitors for the execution of PowerShell scripts named 'deploy_gpo.ps1' from the %TEMP% directory, PowerShell interactions with the NETLOGON share for malware distribution, creation of ScheduledTasks.xml via PowerShell (a common GPO manipulation technique), and the subsequent enforcement of policy changes using 'gpupdate /force' invoked by scripting engines.
Detects attempts to terminate security-related processes (AV/EDR) using common administrative tools including taskkill.exe, wmic.exe, and PowerShell Stop-Process. This behavior is frequently observed during the pre-encryption phase of ransomware attacks, such as Nova and Gentlemen, to evade detection.
Detects lateral movement activities associated with The Gentlemen ransomware group. The rule monitors for the execution of PowerShell scripts named 'deploy_gpo.ps1' from the %TEMP% directory, PowerShell interactions with the NETLOGON share for malware distribution, creation of ScheduledTasks.xml via PowerShell (a common GPO manipulation technique), and the subsequent enforcement of policy changes using 'gpupdate /force' invoked by scripting engines.
Detects the specific sequence of administrative utilities used by Gentlemen ransomware to seize control of files before encryption. This involves using 'takeown.exe' to claim ownership, 'icacls.exe' to grant full access to the Everyone group, and 'attrib.exe' to remove read-only file attributes, a common precursor to mass file encryption.
Detects the mass termination of security, backup, database, and virtualization services and processes. The rule monitors for the use of 'taskkill', 'sc', and 'net stop' commands, targeting a list of processes and services often associated with pre-encryption cleanup activities by ransomware actors to neutralize security tools and data access controls.
Detects the creation of hidden administrative shares (ending in $) mapped to local directories (e.g., C:\Temp) with unrestricted 'Everyone' or 'ANONYMOUS LOGON' permissions. This technique is used by the Gentlemen ransomware to stage malicious binaries for lateral movement and subsequent encryption across the network. The rule monitors for 'net share' commands with specific permission grants, 'icacls' operations modifying access for anonymous users, and registry changes to 'NullSessionShares' configurations.
Detects the creation of scheduled tasks using schtasks.exe initiated by command shells where the task command points to files residing in non-standard or user-writable directories such as \Users\Public\, \PerfLogs\, or \ProgramData\. This pattern is frequently utilized by malware loaders like SocGholish, GootLoader, and various ransomware strains to achieve persistence following initial compromise.
Detects the execution of Nova ransomware (formerly RALord) by monitoring for its specific modular command-line interface arguments, which include file encryption commands, ransom note deployment, and specific ransom note filenames. The rule monitors process creation events for strings like 'encrypt-all', 'encrypt-path', 'readme-add', '--workers', and the presence of the 'README_NOVA.me' ransom note or unique file extensions associated with its encryption activity.
Detects a sequence where an AWS Secrets Manager secret is retrieved via CloudTrail, followed within 30 minutes by an EDR-monitored process initiating an outbound network connection on a non-standard port (not 80 or 443). This behavior is consistent with an adversary using stolen credentials to pivot into a persistent command-and-control channel.
This rule detects the suspicious combination of PowerShell scripts executing download commands (Invoke-WebRequest, etc.) while initiated by scripting hosts (wscript.exe, cscript.exe), followed by activity associated with remote support tools (LogMeIn, ConnectWise, etc.). It also identifies network connections associated with these remote management platforms, suggesting potential unauthorized remote access or tool staging.
Detects outbound network requests to Google Gemini AI API endpoints from processes that are not common web browsers or known development tools. This behavior is indicative of unauthorized use of LLM services by non-browser applications, such as the RatHat UI-automation module, for processing sensitive data or automation tasks.
Detects a browser process downloading an APK installer file from a source other than official Google Play infrastructure. This behavior is commonly associated with smishing, malvertising, and redirection to deceptive third-party application portals used to distribute malware-laced APK droppers.
Detects endpoint network activity characterized by a host connection to the Telegram Bot API followed by a connection to a Vercel-hosted domain within 30 minutes. This behavior is indicative of a multi-stage infection chain where adversaries use Telegram for command-and-control communication or victim validation, followed by the retrieval of malicious payloads or lures from disposable infrastructure like Vercel.
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
Detects HTTP requests and responses involving the download of an executable file named 'ClaudeDesktop.exe' from the 'claude.ai' host, which is indicative of a malicious campaign distributing SectopRAT.
Detects potential malicious activity where a process associated with a Claude agent (or a downloader utility) references a 'SKILL.md' configuration file. This behavior is indicative of a poisoned skill file being used to trigger unauthorized payload downloads or re-establish persistence.
Detects network activity associated with the JWR/Outsider phishing kit, which leverages legitimate e-commerce platform parameters (e.g., Shopify/WooCommerce 'cart_data') to mimic storefront infrastructure. The rule correlates requests containing these e-commerce parameters with the loading of the phishing kit's client-side engine scripts or WebSocket workers from the same host, indicating the use of a compromised or malicious storefront-mimicry domain.
Detects outbound network connections to known JWR phishing framework endpoints. The rule identifies suspicious interaction sequences, including initial beaconing via 'addClick' or 'getSyncSettings' followed by exfiltration of sensitive data (payment card info, OTPs) through POST requests to 'the_final_interface' or 'addCvv', or via a specific WebSocket channel pattern.
Page 157 of 1871

