Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation of scheduled tasks using Event ID 4698 or command-line execution of schtasks.exe. The rule specifically looks for tasks created in suspicious paths such as AppData or ProgramData, or tasks configured to run with highest privileges and/or marked as hidden, which are common indicators of persistence mechanisms used by adversaries.
Detects anomalous Kerberos service ticket (TGS) requests or successful logons where the corresponding Ticket Granting Ticket (TGT) request (Event ID 4768) is absent within the monitored window. This pattern is a primary indicator of offline-forged Kerberos tickets, such as those generated by Mimikatz, which bypass legitimate KDC interaction for ticket issuance.
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
Detects the creation of scheduled tasks using Event ID 4698 or command-line execution of schtasks.exe. The rule specifically looks for tasks created in suspicious paths such as AppData or ProgramData, or tasks configured to run with highest privileges and/or marked as hidden, which are common indicators of persistence mechanisms used by adversaries.
Detects anomalous Kerberos service ticket (TGS) requests or successful logons where the corresponding Ticket Granting Ticket (TGT) request (Event ID 4768) is absent within the monitored window. This pattern is a primary indicator of offline-forged Kerberos tickets, such as those generated by Mimikatz, which bypass legitimate KDC interaction for ticket issuance.
This rule detects the suspicious execution of rundll32.exe or regsvr32.exe, which are commonly abused as Living-off-the-Land Binaries (LOLBins). It identifies potential malicious activity by analyzing command-line arguments for patterns like remote URL requests, usage of scrobj.dll, JavaScript protocols, or specific Squiblydoo attack patterns. Additionally, it monitors for these binaries being executed by parents other than explorer.exe, which is indicative of potential process injection or proxy execution.
Detects attempts to access or dump the memory of the Local Security Authority Subsystem Service (LSASS) process, a technique commonly used by adversaries to harvest domain credentials and clear-text passwords from memory.
Detects lateral movement techniques leveraging Windows Management Instrumentation (WMI). The rule identifies instances where the WMI provider host, WmiPrvSE.exe, spawns common administrative or interactive shell tools (e.g., cmd.exe, powershell.exe). This pattern is consistent with the abuse of Win32_Process.Create() via WMI/DCOM/RPC for remote command execution, a method frequently utilized by frameworks like Impacket (wmiexec.py) for fileless, agentless lateral movement.
This rule detects potential RDP brute force and password spraying attacks by correlating Windows Event ID 4625 (failed logins) and 4624 (successful logins) via RDP (Logon Type 10). It monitors for high volumes of failed attempts across multiple accounts or high volume of failed attempts from a single source, followed by successful authentication from the same source.
Detects unauthorized usage of the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, which are required for the DCSync technique. The rule monitors for Windows Event ID 4662 (Object Access) where a non-domain controller account attempts these replication operations, typically indicative of credential dumping and domain compromise.
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (LSASS) process with access rights consistent with credential dumping (e.g., PROCESS_VM_READ, PROCESS_ALL_ACCESS). This rule also specifically flags the use of well-known tools and techniques such as Mimikatz, ProcDump, and the abuse of rundll32.exe with comsvcs.dll for memory extraction, which is indicative of OS Credential Dumping (T1003.001).
This rule detects persistence mechanisms by monitoring additions to Windows Registry Run keys or files created in the user's Startup directory. It specifically flags entries that target suspicious locations (e.g., Temp, AppData, Public) or attempt to execute encoded commands using PowerShell or CMD.
This rule detects potential lateral movement indicative of PsExec or similar administrative tools. It identifies the combination of remote service installation (often using ADMIN$ or Temp paths), access to administrative shares (ADMIN$ or C$), and the execution of a process spawned by services.exe, which is characteristic of the remote service control manager performing remote service starts.
This rule detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to perform actions associated with ransomware, such as deleting volume shadow copies, deleting the backup catalog, or disabling system recovery features. This is a common precursor to data encryption to prevent the user from restoring files.
Detects potential Cobalt Strike or Sliver command and control (C2) beaconing behavior by analyzing network proxy, firewall, and flow logs for common C2 URI patterns, known malicious JA3/JA3S TLS fingerprints, and consistent periodic communication intervals (low jitter) characteristic of automated beacons.
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) where a single user requests tickets for multiple distinct Service Principal Names (SPNs) using weak RC4 (0x17) encryption. This behavior is highly characteristic of Kerberoasting, a technique used by adversaries to harvest service account tickets for offline cracking.
This rule detects potential illicit consent grants to OAuth applications within Azure AD. It identifies applications requesting high-risk scopes (such as Mail.Read, Files.ReadWrite.All, etc.) that are not verified by a publisher, are granted by non-admin users, and subsequently exhibit high volumes of graph API calls (suggestive of unauthorized data access or exfiltration).
Detects the abuse of signed Windows system binaries (LOLBins: certutil, mshta, regsvr32, rundll32, bitsadmin, msiexec) through the identification of command-line arguments that suggest malicious activity, such as downloading remote content, decoding files, executing scriptlets, or loading DLLs from temporary storage directories.
This rule detects potential DNS tunneling activity by analyzing DNS query logs for high entropy in subdomains, elevated volumes of TXT/NULL record types, and frequent NXDOMAIN responses. This pattern is characteristic of command-and-control (C2) or data exfiltration techniques using tools like dnscat2 or iodine, which encode data into DNS query labels.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell. The rule looks for command-line arguments referencing AMSI-related memory structures, methods, and DLLs such as AmsiUtils, AmsiScanBuffer, AmsiInitFailed, and amsi.dll. Bypassing AMSI is a common technique used by attackers to execute malicious scripts and deploy fileless payloads, such as Cobalt Strike or Sliver, while avoiding detection by endpoint security solutions.
This rule detects potential container escape and privilege escalation attempts within a Kubernetes environment by monitoring for the creation of privileged pods, dangerous host mounts (such as /var/run/docker.sock or hostPath root mounts), and the use of escape-oriented utilities like nsenter or chroot, or access to the host's filesystem via /proc/1/root.
