Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of the Windows built-in utility mshta.exe when it is used to load remote HTA files or scripts via HTTP/HTTPS URLs, or when it is directly spawned by Microsoft Office applications (Word/Excel). This behavior is characteristic of malicious document macros or phishing-based initial access where mshta is used as a proxy to execute code and evade security controls.
Detects the loading or service registration of known vulnerable or malicious signed drivers commonly used in Bring Your Own Vulnerable Driver (BYOVD) attacks. These drivers are leveraged by adversaries to gain kernel-level privileges, bypass security controls, and terminate endpoint protection agents.
Detects the use of bitsadmin.exe to initiate file transfers from remote URLs to sensitive or writable system directories, or the use of /SetNotifyCmdLine to define a command to execute upon job completion. These techniques are often used by adversaries to download payloads or establish persistence via BITS jobs.
Detects execution of the Microsoft Connection Manager Profile Installer (cmstp.exe) with suspicious command-line parameters (using remote INF files via UNC or HTTP) or when it spawns unexpected child processes, both of which are indicative of potential bypass of User Account Control (UAC) or security controls.
Detects the execution of diskshadow.exe with the /s (scripted) flag, followed by file access to sensitive Windows credential files (ntds.dit or SAM). This behavior indicates the abuse of the Windows Diskshadow utility to create a volume shadow copy for the purpose of offline credential exfiltration.
Detects the invocation of Windows Subsystem for Linux (WSL) binaries (wsl.exe or wslconfig.exe) using command-line arguments that enable arbitrary command execution, such as -e, --exec, or shell interpreters (bash -c, sh -c), or web-based retrieval tools like curl/wget. This technique is often used to execute commands or download payloads within a Linux environment on Windows, potentially bypassing security controls focused on native Windows processes.
This rule detects potentially suspicious activity involving conhost.exe, a process typically associated with console applications. It identifies conhost.exe instances running from suspicious paths (e.g., Temp, Downloads, AppData) or launched by unexpected parent processes. Additionally, it detects scenarios where conhost.exe acts as the parent process to common command-line or scripting utilities, which is an atypical behavior often indicative of an attempt to obscure malicious command execution.
This rule detects potential 'Squiblydoo' attacks where regsvr32.exe is used to execute remote scriptlets via HTTP/HTTPS or loads the 'scrobj.dll' library in an unusual manner, such as without a local DLL file path, which is a common indicator of bypassing application allowlisting.
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
Page 176 of 1871


