Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule identifies potential RDP-based lateral movement by detecting when a single user account successfully authenticates to multiple distinct hosts using LogonType 10 (RemoteInteractive) within a 1-hour time window. A threshold of three or more distinct hosts is used to flag activity that deviates from typical single-host RDP usage.
Detects the use of legitimate Windows binaries (LOLBins) certutil.exe and bitsadmin.exe for suspicious activities such as downloading files via URL or decoding encoded files. This rule explicitly excludes known legitimate administrative activity originating from Microsoft Configuration Manager (SCCM).
Detects the initialization of cloud synchronization tools like rclone or MEGAsync, accompanied by the creation of configuration files and subsequent high-volume network activity directed toward common cloud storage providers, indicative of unauthorized data exfiltration.
Detects execution of rundll32.exe and regsvr32.exe with command lines indicative of living-off-the-land techniques, including usage of remote scriptlets, URLs, JavaScript, and execution from non-standard system paths, which are often used for proxy execution or to bypass security controls.
Detects the creation of Windows scheduled tasks that include suspicious interpreters (PowerShell, cmd.exe, rundll32) or execution paths located in common attacker-writable directories (Temp, AppData, ProgramData), which is a common technique for persistence and command-and-control re-establishment.
Detects a single user account performing an unusually high volume of Kerberos Service Ticket (TGS) requests (Event ID 4769) within a short window, specifically using RC4 encryption (0x17). This behavior is highly characteristic of Kerberoasting, where attackers request tickets for various service principal names (SPNs) to perform offline password cracking.
Detects persistence attempts by monitoring modifications to Windows registry run keys (Run, RunOnce, Winlogon Shell/Userinit) or file creation within the Startup folder. It alerts when these locations are updated to reference suspicious file paths (Temp/AppData) or execute scripts (vbs, ps1, js, wsf, bat, hta).
Detects network connections originating from or connecting to hosts that utilize known Cobalt Strike default JA3 or JA3S TLS fingerprints. These fingerprints are indicative of Cobalt Strike's default beacon communication patterns.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that point to suspicious script execution, encoded commands, or files located in commonly abused writable directories like Temp or ProgramData. This behavior is indicative of potential persistence mechanisms.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that point to suspicious script execution, encoded commands, or files located in commonly abused writable directories like Temp or ProgramData. This behavior is indicative of potential persistence mechanisms.
Detects the abuse of the Windows Background Intelligent Transfer Service (BITS) via the bitsadmin command-line tool or PowerShell's Start-BitsTransfer to download files (such as .exe, .dll, or .ps1) or facilitate potential persistence. Adversaries use these methods to transfer malicious payloads stealthily in the background or to maintain persistence on a compromised host.
Detects the loading of known-vulnerable signed drivers typically associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. These drivers are frequently abused to gain kernel-mode privileges, allowing attackers to disable or terminate EDR, antivirus, and other security processes.
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
Detects the execution of PowerShell with suspicious command-line arguments often used by adversaries for obfuscation, evasion, or in-memory code execution, such as encoded commands, hidden windows, and downloading external content.
This rule detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos Service Ticket (TGS) requests (event ID 4769) for non-machine service accounts, specifically focusing on tickets encrypted with RC4 (etype 23). A high count of ticket requests or distinct Service Principal Names (SPNs) requested by a single client in a short period is characteristic of an adversary attempting to harvest hashes for offline cracking.
Detects the creation of scheduled tasks using schtasks.exe that either trigger on user logon or startup and point to common writable directories (e.g., Temp, AppData), or tasks created with a remote system argument, which is frequently used by adversaries for persistence or lateral movement.
This rule detects the use of native Windows utilities certutil.exe and bitsadmin.exe for potentially malicious purposes. Specifically, it flags certutil.exe being used for decoding or cached URL operations, and bitsadmin.exe being used to initiate file transfers from remote URLs or network paths. These tools are commonly abused by attackers for file staging, ingress tool transfer, and deobfuscation of malicious payloads.
This rule detects the creation of named pipes with names patterns commonly associated with post-exploitation frameworks, such as Cobalt Strike and Sliver. These frameworks frequently use specific, sometimes randomized, pipe patterns for inter-process communication, lateral movement, or command and control (C2) operations. Monitoring these pipe names can help identify malicious activity occurring within a compromised environment.
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
Page 172 of 1871

