Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation or modification of Google Cloud Config Connector (KCC) IAM resources (IAMPolicyMember, IAMPartialPolicy, IAMPolicy) that assign high-privilege roles like 'roles/owner' or 'roles/resourcemanager.organizationAdmin'. This monitors for potential privilege escalation where a low-privilege actor leverages the KCC controller's high-privilege service account to perform unauthorized IAM binding changes on Google Cloud resources.
Detects the creation of suspicious scheduled tasks using the Windows schtasks.exe utility. The rule flags tasks that are configured to run as SYSTEM, include PowerShell encoded commands, or target directories commonly used for persistence such as Temp, AppData, or Public.
Detects the abuse of built-in Windows binaries 'regsvr32.exe' and 'msbuild.exe' for proxy execution. Specifically, it flags 'regsvr32.exe' loading remote scriptlets via HTTP and 'msbuild.exe' processing project files containing inline tasks, which are common techniques used to execute arbitrary malicious code while bypassing security controls.
This rule detects potential persistence mechanisms involving the creation of 'Locked' registry keys within Software\Classes and subsequent use of Run registry keys that reference 'Locked://' URIs. It also identifies suspicious execution of rundll32.exe utilizing specific CLSID-based command line arguments associated with the '{CFDC57BA-1705-45AF-BA10-EFC3D592982B}' identifier, often linked to malicious activity patterns.
Detects the creation of suspicious scheduled tasks using the Windows schtasks.exe utility. The rule flags tasks that are configured to run as SYSTEM, include PowerShell encoded commands, or target directories commonly used for persistence such as Temp, AppData, or Public.
This rule detects attempts by an attacker to disable or modify Windows security software and features. It monitors for three distinct behaviors: execution of 'Set-MpPreference' to modify Windows Defender settings (exclusions or real-time monitoring), execution of 'sc.exe' to stop security-related services (such as EDR or AV services), and direct modification of Windows registry keys to disable Windows Defender components.
Detects the abuse of Windows Management Instrumentation (WMI) to execute processes via wmic.exe or WmiPrvSE.exe, often combined with obfuscated command-line arguments such as encoded PowerShell or CMD commands.
Detects unauthorized processes (other than known browsers like Chrome, Edge, or Firefox) attempting to access sensitive browser files such as 'Login Data', 'Cookies', or 'Web Data'. This behavior is commonly associated with credential stealing or browser session hijacking.
Detects OAuth token requests associated with the 'PDF Identity Verifier' application or specific client IDs, often used by malicious browser extensions or phishing applications to exfiltrate sensitive Google account data, specifically Gmail and user profile information.
Detects suspicious modifications to Windows Registry keys associated with URL protocol handlers or automatic startup mechanisms. Adversaries often use custom URL schemes or registry run keys to maintain persistence or execute malicious code when a specific protocol is invoked or upon user logon.
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) using either the built-in 'comsvcs.dll' library via 'rundll32.exe' or by requesting specific sensitive process access rights to 'lsass.exe' from unauthorized processes.
Detects user-initiated execution of scripts or binaries directly from the root of a drive letter. This pattern is commonly associated with phishing campaigns delivering malicious payloads via mounted ISO or IMG files, which allow attackers to bypass mark-of-the-web or macro security controls.
Detects the installation or execution of common remote access tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop) using silent or unattended installation flags. This rule explicitly excludes activity originating from known administrative and management platforms such as Microsoft Intune and SCCM.
Detects instances where rundll32.exe loads a DLL file named Use.dll from a subdirectory named 'ComponentsFolder' within the AppData directory. This pattern is indicative of sandbox evasion techniques used by malware, such as the DarkMe RAT, where the DLL acts as an anti-sandbox gateway to check the execution environment.
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) using either the built-in 'comsvcs.dll' library via 'rundll32.exe' or by requesting specific sensitive process access rights to 'lsass.exe' from unauthorized processes.
Detects user-initiated execution of scripts or binaries directly from the root of a drive letter. This pattern is commonly associated with phishing campaigns delivering malicious payloads via mounted ISO or IMG files, which allow attackers to bypass mark-of-the-web or macro security controls.
Detects the installation or execution of common remote access tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop) using silent or unattended installation flags. This rule explicitly excludes activity originating from known administrative and management platforms such as Microsoft Intune and SCCM.
This rule detects high-risk AWS API calls that are commonly associated with privilege escalation and persistence. It monitors for the creation of overly permissive IAM policies (wildcard permissions), the creation of new access keys for existing users, and suspicious AssumeRole operations.
Detects the use of legitimate Windows binaries (certutil.exe and bitsadmin.exe) to download files from remote URLs to sensitive or common staging directories (Temp, AppData, ProgramData). Attackers frequently abuse these built-in tools for 'living off the land' (LotL) to retrieve malicious payloads or secondary tools while bypassing traditional signature-based detection.
This rule detects attempts to steal the Active Directory database (ntds.dit) and associated security files by creating volume shadow copies using native Windows utilities like ntdsutil, vssadmin, or wmic. It also monitors for direct file system access or creation attempts related to these sensitive database files within shadow copy paths.
Detects persistence attempts on Windows by monitoring for modifications to common Registry Run/RunOnce keys or the creation of executable files within the user startup directory. The rule excludes common legitimate processes like msiexec.exe, trustedinstaller.exe, and explorer.exe to minimize false positives.

