Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the misuse of the legitimate odbcconf.exe utility via the /A switch combined with the REGSVR action. Attackers leverage this behavior to execute malicious DLLs, often utilizing response files or executing from non-standard directories to bypass application control policies.
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
Detects the creation of a scheduled task configured to run under SYSTEM or a Service account, where the triggering process is not a recognized system binary (e.g., taskeng.exe, schtasks.exe). This pattern is often used for persistence or lateral movement by bypassing standard administrative task creation tools.
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
Detects the use of sdbinst.exe to install a shim database (.sdb) file from non-standard, user-writable directories (such as Temp, AppData, Downloads, Users Public, or ProgramData). Adversaries use application shimming to achieve persistence or privilege escalation, and custom shims are typically expected to reside in system-protected AppPatch directories.
Detects network connection attempts to known malicious infrastructure, specifically targeting suspicious domains and an IP address associated with command and control (C2) activity. The rule monitors endpoint network events for communication with specified malicious URLs or a hardcoded IP.
This rule detects potentially malicious network activity by monitoring for specific query parameters ('bmodule', 'smodule', 'lmodule', 'task', 'upload.php') in web requests or communication with a specific known-malicious IP address ('62.60.226.50'). This pattern is characteristic of C2 (Command and Control) traffic or unauthorized file staging/upload operations.
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
Detects execution of MeshAgent binaries when initiated by common scripting or application processes (e.g., java, sh, bash, python) or when displaying suspicious command-line patterns indicative of unauthorized remote access or download activity, particularly in environments like WebLogic or PeopleSoft.
Detects a specific pattern associated with AvisLoader or similar malware: a device establishes a network connection to known Cloudflare Tunnel infrastructure domains (trycloudflare.com or workers.dev), followed by the creation and execution of an executable file (.exe, .dll, or .scr) in user-writable directories such as Downloads, AppData, or Temp within a 15-minute window.
This rule detects the presence and execution of known suspicious files (hashes provided) or specific malicious artifacts, such as 'hmn_hook.dll' being loaded, or the execution of binaries named 'auto.exe' and '78324.exe' associated with specific command-line arguments. It monitors file events, image loads, and process creation to identify potential malware activity.
This rule identifies instances of screen capture events initiated by processes that have previously engaged in network communication with known Remote Management Tool (RMM) domains. By correlating network activity with suspicious endpoint events, it flags potential unauthorized screen scraping performed by tools often abused by attackers for post-compromise reconnaissance.
Detects malformed HEIF/HEIC image files with anomalous ftyp/box structure consistent with the libheif memory corruption exploit (CVE-2026-32882) used against Discourse forum image upload endpoints
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
Detects the use of Windows Management Instrumentation (WMI) utilities (wmic.exe or wmiprvse.exe) to perform command execution or establish persistence via WMI event subscriptions, filters, or consumers. Attackers often abuse these WMI features to execute arbitrary commands, run payloads, or establish persistent backdoors.
Page 167 of 1871




