Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.
Detects potential lateral movement by identifying NTLM authentication (Logon Type 3) to administrative network shares (ADMIN$, C$, IPC$) or high-frequency access to multiple hosts by the same user, which may indicate credential abuse or lateral movement attempts.
This rule detects instances of Kerberos Ticket-Granting Ticket (TGT) requests (Event IDs 4768 and 4769) that utilize the legacy RC4 encryption type (0x17). In modern Active Directory environments where AES is the standard for Kerberos, the use of RC4 can be a strong indicator of a Golden Ticket attack or other unauthorized ticket forging activities, as adversaries often force a downgrade to RC4 for easier offline cracking.
Detects Microsoft Windows Event ID 4662 (Object Access) where specific GUIDs associated with sensitive Active Directory rights (specifically, those related to DCSync or sensitive extended rights) are accessed. The rule filters out events originating from Domain Controllers to identify potentially anomalous access patterns from non-DC endpoints.
Detects modifications to Windows Registry persistence locations (Run, RunOnce, Winlogon Shell/Userinit) where the assigned executable path is located within high-risk directories such as Temp, AppData, or Users Public folders. This is a common technique used by malware for persistence.
This rule detects instances of Kerberos Ticket-Granting Ticket (TGT) requests (Event IDs 4768 and 4769) that utilize the legacy RC4 encryption type (0x17). In modern Active Directory environments where AES is the standard for Kerberos, the use of RC4 can be a strong indicator of a Golden Ticket attack or other unauthorized ticket forging activities, as adversaries often force a downgrade to RC4 for easier offline cracking.
Detects Microsoft Windows Event ID 4662 (Object Access) where specific GUIDs associated with sensitive Active Directory rights (specifically, those related to DCSync or sensitive extended rights) are accessed. The rule filters out events originating from Domain Controllers to identify potentially anomalous access patterns from non-DC endpoints.
Detects modifications to Windows Registry persistence locations (Run, RunOnce, Winlogon Shell/Userinit) where the assigned executable path is located within high-risk directories such as Temp, AppData, or Users Public folders. This is a common technique used by malware for persistence.
Detects the loading of common Windows system DLLs (e.g., version.dll, dbghelp.dll) from suspicious, non-standard directory paths. Such behavior is often indicative of DLL side-loading or hijacking attempts, where an adversary places a malicious DLL with the same name as a legitimate one in a writable directory to influence application execution.
Detects the use of native Windows binaries such as vssadmin.exe, wmic.exe, bcdedit.exe, and wbadmin.exe to inhibit system recovery by deleting shadow copies, clearing backup catalogs, or disabling automatic system recovery.
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from non-reputable/non-Microsoft sources to suspicious directories such as Temp, AppData, or ProgramData, which is a common technique for ingress tool transfer during malware delivery.
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from non-reputable/non-Microsoft sources to suspicious directories such as Temp, AppData, or ProgramData, which is a common technique for ingress tool transfer during malware delivery.
Detects suspicious activity associated with Cobalt Strike Beacon communication, specifically monitoring for known default named pipes and specific user-agent strings commonly used by Cobalt Strike in HTTP/S traffic.
Detects the initiation of a new process where the effective user context is SYSTEM, but the originating process was launched by a non-privileged user account. This behavior is indicative of token manipulation techniques such as token impersonation or theft (e.g., via DuplicateTokenEx or ImpersonateLoggedOnUser) to escalate privileges to SYSTEM.
Detects instances where an alert marked as process injection (T1055) involves an action process that is unsigned and differs from the actor process image, suggesting potential execution of an unauthorized or malicious payload masked by process injection techniques.
Detects AWS CloudTrail and Azure Active Directory (Entra ID) privilege-escalation actions (e.g., attaching policies, creating access keys, adding roles) performed by principals from rare source IPs or associated with low-frequency administrative actions, indicating potentially compromised or unauthorized account activity.
Detects the Sckit supply chain implant reading sensitive credential files from a user's home directory. The rule monitors processes spawned by Node.js or Python interpreters (the primary loaders for the Sckit worm) attempting to access high-value files like SSH keys, .npmrc, .pypirc, and various token storage files, indicating potential credential harvesting behavior.
Detects the abuse of Windows Management Instrumentation (WMI) to execute processes via wmic.exe or WmiPrvSE.exe, often combined with obfuscated command-line arguments such as encoded PowerShell or CMD commands.
