Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the loading of a legitimately signed but vulnerable driver from suspicious directories (e.g., Temp, Downloads) followed closely by the termination of critical security/EDR service processes. This sequence is indicative of Bring Your Own Vulnerable Driver (BYOVD) exploitation used to disable security controls prior to ransomware deployment.
Detects scripting interpreters (wscript.exe, cscript.exe, powershell.exe, python.exe) that perform an outbound network connection to known public Generative AI API endpoints and subsequently modify their own script file on disk. This behavior is indicative of sophisticated malware attempting to rewrite its own source code at runtime to evade signature-based detection.
Detects a credential stuffing attack characterized by a high volume of failed authentication attempts from a small set of source IP addresses followed by a successful authentication within a short timeframe. This behavior is indicative of an attacker attempting to use valid credentials obtained from infostealer logs or credential leaks to gain unauthorized access to accounts.
This rule detects potential lateral movement by identifying a system that initiates SMB connections (port 445) to 5 or more unique destinations, correlated with a Windows Service installation event (Event ID 7045) on the host. This behavior is indicative of an adversary or automated tool using SMB to copy and execute binaries as a service on multiple remote systems.
This rule detects successful user logins from multiple geographical locations (impossible travel) where multi-factor authentication (MFA) was not utilized. This behavior is indicative of credential theft or account takeover attempts.
This rule detects a correlation between an Active Directory Certificate Services (AD CS) certificate request (Event ID 4887) containing certificate attributes (SAN, altname, or UPN) and a subsequent Kerberos TGT request (Event ID 4768) within an hour, where the requested account name does not match the ticket user. This behavior is indicative of potential certificate-based authentication abuse, such as 'ESC1' or 'Golden Certificate' attacks where a certificate is requested and immediately used for credential impersonation.
Detects the use of common administrative tools (vssadmin, wbadmin, wmic, bcdedit, etc.) to perform actions that inhibit system recovery. This includes deleting Volume Shadow Copies, deleting backup catalogs, disabling system recovery boot policies, and stopping backup-related services, which are common behaviors used by ransomware to prevent data restoration.
Detects the installation of a new Windows service where the executable path is located in suspicious or uncommon directories (e.g., Temp, Users, AppData) or uses known living-off-the-land binaries (LotLBin) in the command path. This pattern is commonly used by adversaries for persistence and privilege escalation.
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) using weak encryption (RC4/0x17) directed at multiple unique Service Principal Names (SPNs) from a single host or user within a short timeframe. This behavior is indicative of Kerberoasting, a technique used by attackers to harvest service account credentials for offline brute-force cracking.
Detects a single host or account generating a high volume of LDAP queries (typical of reconnaissance tools like BloodHound/SharpHound) within a 10-minute time window. The rule specifically looks for more than 500 LDAP queries targeted at a limited number of Domain Controllers.
Detects instances where PowerShell is executed with encoded commands, seemingly spawned by a process masquerading as or related to the Microsoft Edge Update Task. The rule specifically monitors for process chains involving 'conhost.exe' with '--headless' arguments and subsequent PowerShell execution containing encoded commands, often associated with obfuscated activity.
Detects NTLM network logon events (Logon Type 3) using the NtLmSsp process where the key length is zero. This pattern is often indicative of Pass-the-Hash (PtH) attacks where the adversary uses a NTLM hash for authentication without knowing the original plaintext password.
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
Detects usage of the Windows certutil.exe utility with flags commonly used by adversaries to download files from remote URLs or decode base64 encoded files. These techniques are often utilized for ingress tool transfer or deobfuscating malicious payloads.
Detects the execution of PowerShell commands that enumerate files within sensitive user directories such as Desktop, Downloads, Documents, or OneDrive, using common cmdlets like Get-ChildItem with recurrence or filtering. This behavior is indicative of an adversary attempting to discover or stage files for exfiltration.
Detects instances where a trusted, system-protected executable loads a DLL file from a user-writable or temporary directory that is not digitally signed or has an invalid signature. This is a common indicator of DLL side-loading or DLL hijacking, where an adversary attempts to execute malicious code by placing a malicious DLL in a location searched by a legitimate process.
Detects the use of the BITSAdmin command-line utility to perform file downloads or add files to a transfer job. Adversaries may abuse the Background Intelligent Transfer Service (BITS) for downloading malicious files while evading detection or maintaining persistence.
Detects the use of net.exe or net1.exe to establish an IPC$ share connection. This is a common method for lateral movement and reconnaissance by attackers to verify administrative access or interact with remote systems via SMB. The rule specifically flags commands involving the IPC$ share, with logic to identify if a specific user was specified or if an anonymous session was attempted.
This rule detects rundll32.exe executing a DLL from the ProgramData directory and subsequently establishing five or more outbound network connections to external IP addresses over non-standard ports (excluding 80 and 443) within a one-hour window. This behavior is indicative of a potential malware beaconing or data staging activity using a proxy binary to evade detection.
Detects specific file artifacts associated with an AsyncRAT infection chain that leverages a renamed AutoIT interpreter. The rule looks for the presence of a renamed executable, an encrypted .ini loader script, and an unnamed binary payload staged within a temporary directory, as well as associated batch script activity.
Detects the execution of PowerShell (powershell.exe or powershell_ise.exe) initiated by Windows Script Host (wscript.exe or cscript.exe). The rule specifically looks for common obfuscation and stealth flags such as hidden window style, execution policy bypass, and non-interactive mode, which are often used by malicious scripts to execute code silently.
Page 162 of 1871

