Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the execution of reg.exe with the 'save' command to extract the SAM, SYSTEM, or SECURITY registry hives to disk. This technique is commonly used by attackers to offline extract credential hashes, facilitating pass-the-hash attacks and lateral movement.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
Detects the execution of PowerShell with encoded commands (e.g., -EncodedCommand or -enc) combined with common download cradle indicators such as IEX, Net.WebClient, or DownloadString. This combination is highly indicative of fileless malware execution, initial access payload staging, or defense evasion techniques often employed by threat actors to bypass command-line monitoring.
Detects unauthorized directory replication requests (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) made against Active Directory by a user or computer account that is not a domain controller. This behavior is indicative of a DCSync attack, typically performed by tools like Mimikatz to extract password hashes for all domain accounts.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the task is configured to run in the security context of the SYSTEM account or executes suspicious binaries like PowerShell, mshta, or other living-off-the-land binaries. This behavior is indicative of potential persistence mechanisms employed by adversaries.
Detects the abuse of the built-in Windows utility 'certutil.exe' to download remote files using URL cache functionality or to deobfuscate base64-encoded payloads. This is a common LOLBin (Living-off-the-Land Binary) technique used in phishing loaders, malware delivery, and post-exploitation toolkits.
Detects the creation of WMI permanent event subscriptions, including the instantiation of __EventFilter, __EventConsumer, and __FilterToConsumerBinding classes. This mechanism is frequently used by adversaries for fileless and reboot-resilient persistence, as it allows for arbitrary code execution triggered by system events.
Detects the deletion of Volume Shadow Copies and disabling of Windows boot recovery options using native administrative utilities such as vssadmin, wmic, powershell, wbadmin, and bcdedit. This behavior is frequently associated with pre-encryption activities in ransomware attacks to prevent system restoration.
This rule detects potential Kerberoasting activity by monitoring Windows Security Event ID 4769 for TGS service ticket requests using weak RC4 encryption (etype 0x17). It correlates these individual requests to identify a single user account requesting an abnormally high volume of service tickets within a 10-minute window, which is highly characteristic of automated SPN enumeration and cracking tools like Rubeus or Impacket.
Detects instances where a digitally signed executable loads a DLL from a non-standard, user-writable directory (such as Downloads, Desktop, Temp, or AppData). This behavior is characteristic of DLL side-loading, an evasion technique used to execute malicious code by placing a rogue DLL in a location where a legitimate binary might search for its dependencies, often used by threat actors to persist or maintain covert execution.
Detects the granting of OAuth application permissions or app role assignments in Azure AD/Entra ID that include high-privilege scopes such as Mail.Read, Directory.ReadWrite.All, or offline_access. This behavior is characteristic of consent phishing attacks, where adversaries trick users into granting permissions to a malicious application to maintain persistent access to resources like email or tenant directories.
Detects potential AWS IAM privilege escalation attempts by identifying suspicious modifications to IAM policies, roles, or trust relationships, as well as unauthorized role assumption events. This rule monitors for activities such as attaching high-privilege policies (e.g., AdministratorAccess), creating new policy versions, and modifying trust policies to allow unexpected principals, which are common indicators of post-compromise activity designed to expand access within an AWS environment.
Detects lateral movement activities involving the use of PsExec-style tools or the manual creation of remote services to execute commands. This behavior often leverages SMB admin shares (ADMIN$, C$) to drop and execute binaries or scripts, a technique frequently observed in ransomware campaigns and red team engagements.
This rule detects artifacts and command-line patterns associated with Impacket utility suite modules, specifically wmiexec.py, smbexec.py, and secretsdump.py. These tools are commonly used by adversaries for remote command execution, lateral movement, and dumping of sensitive domain or system credentials.
Detects the execution of legitimate developer utilities msbuild.exe, regasm.exe, and regsvcs.exe in manners consistent with malicious proxy execution. This includes the use of inline tasks in project files, remote network-sourced project files, or specific command-line arguments (such as /codebase or /unregister) that suggest the abuse of these binaries to execute arbitrary code or bypass application control mechanisms, while excluding known legitimate developer-related parent processes and build workflows.
Detects the suspicious execution of common Windows system binaries (LOLBAS) often used for proxying malicious code execution or deobfuscating payloads. This includes regsvr32.exe for remote scriptlet execution, mshta.exe for remote HTA execution, rundll32.exe for JavaScript or DLL function execution, and certutil.exe for decoding or retrieving remote files.
Detects Microsoft Office applications or scripting engines spawning schtasks.exe to create or modify a scheduled task that executes as the SYSTEM user upon system startup or login. This behavior is highly indicative of persistence mechanisms used by malicious documents or scripts.
This rule detects potential Kerberoasting activity by monitoring Kerberos TGS requests (Event ID 4769) that use RC4 encryption (0x17 or 17). It identifies accounts requesting TGS tickets for a large number of unique Service Principal Names (SPNs), excluding requests for host-based services (ending in $). High volumes of such requests from a single user are indicative of an attempt to gather service tickets for offline password cracking.
This rule detects potential AS-REP Roasting attempts by identifying an unusually high volume of Kerberos AS-REQ requests (Event ID 4768) where the preauthentication type is set to 0. These requests are grouped by source IP or client address, and alerts are triggered when the number of unique accounts targeted or the total request count exceeds defined thresholds. AS-REP Roasting is an attack technique that attempts to retrieve a TGT for user accounts that have Kerberos preauthentication disabled, making them susceptible to offline brute-force password cracking.
This rule detects potential Kerberoasting activity by monitoring Kerberos TGS requests (Event ID 4769) that use RC4 encryption (0x17 or 17). It identifies accounts requesting TGS tickets for a large number of unique Service Principal Names (SPNs), excluding requests for host-based services (ending in $). High volumes of such requests from a single user are indicative of an attempt to gather service tickets for offline password cracking.
This rule detects potential AS-REP Roasting attempts by identifying an unusually high volume of Kerberos AS-REQ requests (Event ID 4768) where the preauthentication type is set to 0. These requests are grouped by source IP or client address, and alerts are triggered when the number of unique accounts targeted or the total request count exceeds defined thresholds. AS-REP Roasting is an attack technique that attempts to retrieve a TGT for user accounts that have Kerberos preauthentication disabled, making them susceptible to offline brute-force password cracking.

