Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances of explorer.exe being launched by a parent process other than expected system processes (explorer.exe, userinit.exe, or winlogon.exe). This behavior is highly irregular for Windows desktop environments and may indicate process injection or malicious process masquerading.
Detects instances where npm processes (install, preinstall, or postinstall) spawn suspicious child processes such as shell interpreters (cmd, powershell, bash, sh), network utilities (curl, wget), or scripting interpreters (python). This behavior is often associated with malicious npm package installation or software supply chain compromise where post-install scripts are used to gain persistence or download secondary payloads.
Detects the execution of PowerShell with hidden window arguments from explorer.exe, typically indicative of ClickFix social engineering where a user is tricked into pasting malicious commands into the Windows Run dialog.
Detects instances where processes (excluding known legitimate .NET processes) load common .NET runtime modules (e.g., clr.dll, mscoree.dll) followed by remote process injection or handle-based process access, which is often indicative of reflective assembly loading used by loaders like PIVOTPIPE to execute malicious code within a target process.
Detects a Node.js server process (e.g. "next-server", "node.exe") spawning
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
This rule detects unauthorized attempts to perform a DCSync attack by monitoring for Active Directory Event ID 4662. It triggers when an account that is not a recognized domain controller (which typically end with a '$' sign) successfully requests replication data using the Directory Replication Service (DRS) GetNCChanges rights. This behavior is a common indicator of credential dumping via tools like Mimikatz.
Detects the execution of known privilege escalation tools and the use of specific Windows privilege keywords (such as SeImpersonatePrivilege) often associated with access token manipulation and token impersonation attacks to elevate privileges to SYSTEM.
Detects instances where rundll32.exe is executed with suspicious command-line parameters that are often associated with malicious activity. This includes attempts to dump memory (comsvcs.dll), utilize specific protocols (url.dll), execute JavaScript, or leverage common writeable directories for payload staging, all of which are common techniques used by attackers to proxy execution and evade defenses.
Detects attempts to disable Windows Defender features via PowerShell, terminate critical security services using administrative tools like sc.exe or net.exe, or inject/patch AMSI (Antimalware Scan Interface) within a process context to evade detection.
This rule detects Terraform CLI activity interacting with suspicious domains or modules, specifically targeting known repositories or namespaces (e.g., gocommunity.io, gogets.dev). It monitors for Terraform initialization or application patterns referencing these domains in process command lines, as well as the creation of Terraform provider files within these specific namespaces. This behavior is indicative of potential supply chain compromise involving malicious Terraform modules or dependencies.
Detects the execution of 'go' or 'go.exe' with 'run' commands originating from infrastructure automation or orchestration tools such as Terraform, Docker, or other related automation processes. This pattern may indicate the execution of arbitrary Go code or modules in environments where infrastructure code is being managed or deployed.
Detects the execution of terraform.exe or go.exe on developer hosts, which acts as a precursor to the malicious Terraform provider campaign (Graphalgo) that targets cloud credentials.
Detects suspicious activities associated with ysoserial.net gadget chain exploitation targeting SharePoint's w3wp.exe process. The rule correlates the loading of specific .NET assemblies (PresentationFramework, System.Xaml, System.Data.Services) with the subsequent execution of command shells (cmd, powershell) or the presence of common ysoserial.net-related strings (ActivitySurrogateSelector, LosFormatter) within command lines originating from the w3wp.exe process, indicating a potential web shell.
Detects the execution of the Graphalgo RAT second-stage payload. The rule identifies the spawning of a detached 'go run .' process, which performs an ephemeral key exchange using a hardcoded public key before C2 establishment. It also correlates this activity with parent processes common in software build environments (npm, terraform, go) to differentiate malicious staging from developer activity.
Detects network connection attempts to 'third-party.com', which was historically a common documentation placeholder domain but has since been acquired by attackers to serve malicious infrastructure. This rule flags processes interacting with this domain, identifying potential exploitation via copy-pasted code or documentation examples.
Detects the execution of the C# compiler (csc.exe) initiated by PowerShell. This behavior is often indicative of in-memory compilation and execution of malicious code, bypassing traditional file-based detection.
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
This rule detects unauthorized attempts to extract credentials from the Local Security Authority Subsystem Service (LSASS) process. It monitors for two distinct techniques: non-standard processes opening handles to lsass.exe with sensitive access rights (credential-dumping) and the use of rundll32.exe to invoke the MiniDump function within comsvcs.dll against lsass.exe.
Detects directory replication requests (Event ID 4662) using DS-Replication-Get-Changes or DS-Replication-Get-Changes-All GUIDs initiated by a computer account that is not a recognized domain controller. This behavior is indicative of a DCSync attack, where an adversary attempts to pull sensitive credential data directly from Active Directory.
Detects anomalous Kerberos ticket requests that are characteristic of Golden Ticket attacks. The rule flags the use of weak encryption types (e.g., RC4) commonly used in forged tickets even in AES-enforced environments, and direct requests for the KRBTGT service account outside of legitimate ticket renewal operations.
Page 171 of 1871



