Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects potential Adversary-in-the-Middle (AiTM) activity by identifying a successful interactive MFA-protected sign-in followed within 15 minutes by a non-interactive (refresh token) sign-in for the same user from a different IP address, ASN, or User-Agent. This pattern is indicative of session hijacking where an attacker reuses a stolen session token.
Detects MFA relay phishing kits (such as Bluekit) where the MFA challenge is satisfied by an attacker-controlled proxy rather than the legitimate user device. The rule identifies sign-in attempts where the primary authentication request originates from one network location, while the MFA completion step originates from a different network location, and the MFA claim indicates it was satisfied via a proxied token.
Detects instances where a non-browser process initiates network connections to multiple AI service providers and Discord within a 15-minute correlation window, potentially indicating automated data exfiltration or unauthorized interaction with AI platforms using tools other than standard web browsers.
Detects instances where a non-browser process initiates network connections to multiple AI service providers and Discord within a 15-minute correlation window, potentially indicating automated data exfiltration or unauthorized interaction with AI platforms using tools other than standard web browsers.
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
Detects high-volume outbound data transfers (exceeding 100MB) directed towards common cloud storage providers, file sharing services, and AI model endpoints. This behavior is indicative of potential data exfiltration by an adversary using legitimate web services to bypass traditional network security controls.
Detects DNS queries containing long, high-entropy subdomain labels, which are characteristic of DNS tunneling techniques. Adversaries use DNS tunneling to bypass network controls by embedding C2 communications within DNS protocol fields. This rule identifies suspicious query structures, specifically targeting extended length and high character diversity in subdomains while filtering out common CDN domains that exhibit similar structural behaviors.
This rule detects potential DNS tunneling activities used for data exfiltration. It identifies suspicious patterns by monitoring for a sustained, high volume (over 200) of DNS queries containing long, high-entropy encoded strings within the subdomain segment from a single client IP address. Legitimate traffic such as reverse DNS lookups is excluded to minimize noise.
Detects unauthorized processes attempting to access the cloud instance metadata service (169.254.169.254). Adversaries frequently target this endpoint to extract sensitive instance information, such as IAM credentials or configuration data, typically as part of post-exploitation discovery or SSRF-based attacks.
Detects anomalous process execution originating from a Python-based sandbox (such as Semantic Kernel SessionsPythonPlugin in Azure Container Apps) that attempts to break out of the container isolation. The rule monitors for command-line arguments involving interaction with the Docker socket, sensitive host namespaces, or container privilege escalation techniques, indicative of exploitation attempts related to CVE-2026-25592.
Detects instances where AI agent host processes (such as Python, .NET, or IIS worker processes) spawn suspicious child processes like command interpreters or common system utilities. This behavior is indicative of potential Remote Code Execution (RCE) via prompt injection, where an AI agent is manipulated into executing arbitrary system commands.
Detects the suspicious retrieval and immediate execution of Agentic AI configuration files (e.g., AGENTS.md, KNOWLEDGE.md) from remote sources using common command-line utilities. This pattern is indicative of an adversary injecting malicious agent instructions or unauthorized configurations into an AI environment.
Detects DNS queries to major public LLM API endpoints (OpenAI, Anthropic, Google Generative Language). This may indicate potential use of these services as a command and control (C2) channel or for data exfiltration by insiders or compromised systems, which may bypass traditional security controls.
Detects a high volume of HTTP POST requests to common login endpoints (e.g., /login or /wp-login.php) from a single source IP address within a short time frame, which is indicative of a credential stuffing or automated brute-force attack.
This rule identifies MikroTik devices running vulnerable versions of RouterOS (specifically those older than 7.24) that are susceptible to CVE-2026-84411. This vulnerability involves an integer underflow in the web management HTTP handling, which can lead to unauthenticated remote code execution or denial of service.
Detects incoming web requests containing a 'pagename' parameter with URL-encoded path traversal sequences, which could allow unauthorized file access or directory traversal attacks against WordPress page-template resolution as described in CVE-2026-87902.
This rule detects unauthorized attempts to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. It monitors for common post-exploitation tools (such as procdump, mimikatz, nanodump, and sqldumper) or built-in Windows techniques (using rundll32.exe with comsvcs.dll) that are typically used to extract sensitive credential material from process memory.
Detects the WMI provider host (wmiprvse.exe) spawning common living-off-the-land binaries often associated with command execution or lateral movement.
Detects anomalous patterns of Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting attacks. The rule identifies accounts requesting a high volume of service tickets for distinct Service Principal Names (SPNs), excluding the krbtgt account.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.



