Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the abuse of signed Windows system binaries (LOLBins: certutil, mshta, regsvr32, rundll32, bitsadmin, msiexec) through the identification of command-line arguments that suggest malicious activity, such as downloading remote content, decoding files, executing scriptlets, or loading DLLs from temporary storage directories.
This rule detects potential DNS tunneling activity by analyzing DNS query logs for high entropy in subdomains, elevated volumes of TXT/NULL record types, and frequent NXDOMAIN responses. This pattern is characteristic of command-and-control (C2) or data exfiltration techniques using tools like dnscat2 or iodine, which encode data into DNS query labels.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell. The rule looks for command-line arguments referencing AMSI-related memory structures, methods, and DLLs such as AmsiUtils, AmsiScanBuffer, AmsiInitFailed, and amsi.dll. Bypassing AMSI is a common technique used by attackers to execute malicious scripts and deploy fileless payloads, such as Cobalt Strike or Sliver, while avoiding detection by endpoint security solutions.
This rule detects potential container escape and privilege escalation attempts within a Kubernetes environment by monitoring for the creation of privileged pods, dangerous host mounts (such as /var/run/docker.sock or hostPath root mounts), and the use of escape-oriented utilities like nsenter or chroot, or access to the host's filesystem via /proc/1/root.
Detects potential Golden SAML activity by correlating Azure AD SAML sign-in events for privileged accounts with a lack of corresponding server-side ADFS authentication logs, unusual SAML issuer URIs, lack of on-premises authentication logs, or evidence of direct access to ADFS token-signing certificate private key material.
This rule detects potential DNS tunneling activities often associated with Command and Control (C2) communication. It monitors for anomalous patterns including excessively long DNS query labels, the use of uncommon DNS record types (TXT or NULL), and high volumes of DNS traffic directed towards specific domains. These behaviors are common indicators of data exfiltration or covert beaconing attempts designed to bypass traditional network security controls.
Detects the execution of native Windows utilities such as vssadmin, wmic, wbadmin, and bcdedit used to delete volume shadow copies, the backup catalog, or disable system recovery boot policies. This activity is a common precursor to ransomware encryption to prevent data restoration.
Detects the use of token manipulation APIs (DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser), the 'runas' command for credential switching, or the execution of known security token manipulation tools (e.g., incognito, Tokenvator, Invoke-TokenManipulation). This activity is commonly associated with privilege escalation and token theft.
Detects the use of data archival utilities (7zip, WinRAR) or command-line cloud synchronization tools (Rclone) to stage files in common temporary directories, immediately followed by network connections to known cloud storage endpoints. This pattern is characteristic of pre-encryption exfiltration activities often seen in ransomware campaigns.
Detects legitimate, signed executables from trusted system locations (e.g., System32) loading DLLs from non-standard, user-writable directories (e.g., Temp, AppData). This activity is a classic indicator of DLL side-loading, where an adversary places a malicious DLL in a directory to be picked up by a legitimate application, enabling the execution of malicious code under the context of a trusted process.
Detects suspicious cross-process memory operations where a source process requests process creation/write permissions on a target process (e.g., browsers, explorer.exe, or svchost.exe), followed immediately by the execution of a remote thread injection technique such as CreateRemoteThread, QueueUserAPC, or NtCreateThreadEx within the same process pair.
Detects multiple inbound HTTP requests targeting known vulnerable application paths (e.g., cgi-bin, .env files, actuator gateways, path traversal, WordPress plugins, PHP eval files, and various server administration consoles) from a single source within a short timeframe. This behavior is indicative of an automated scanner or exploit chain attempting to identify and compromise public-facing applications.
Detects high-volume DNS traffic characterized by long, high-entropy subdomain labels, which are often used as a mechanism for command-and-control (C2) communication or data exfiltration via DNS tunneling.
Detects HTTP POST requests directed to OpenAI or Anthropic API endpoints originating from non-browser user agents (e.g., Python requests, curl, Go-http-client). This activity may indicate automated interactions, potentially for malicious purposes such as script-based interaction with LLMs or unauthorized API usage.
Detects repeated, small outbound HTTP/HTTPS requests to an external destination, a behavior characteristic of scripted command-and-control (C2) beaconing where a client periodically polls a server for instructions.
Detects large HTTP POST requests (exceeding 100KB) directed to public LLM API endpoints such as OpenAI or Anthropic. This behavior may indicate potential bulk data exfiltration or unauthorized sharing of sensitive data with external AI providers.
Detects multiple attempts to connect to administrative shares (ADMIN$, C$, IPC$) from a single source within a 60-second window. This pattern is indicative of automated lateral movement or enumeration attempts using the SMB protocol.
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
Detects the use of the built-in Windows utility rundll32.exe to execute the MiniDump functionality within comsvcs.dll against the Local Security Authority Subsystem Service (LSASS). This technique is a common method for attackers to bypass signature-based security tools and obtain sensitive credentials from memory.
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
Detects the abuse of the legitimate Windows system binaries regsvr32.exe and rundll32.exe to execute remote scripts or scriptlets, a technique often used to bypass application control and proxy execution of malicious code (similar to Squiblydoo).


