Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.
Detects modifications to the 'PlugPlay' Windows service using 'sc.exe', specifically involving changes to the binary path (binpath) and subsequent service status changes (start/stop) within a short timeframe (30 minutes). This behavior is often associated with the persistence or hijacking of services to execute malicious files, specifically targeting Microsoft Office or Copilot-related process names.
Detects anomalous file activity associated with the PaperCut application (pc-app.exe), characterized by the creation of numbered binary chunks (.bin) followed by the creation of a status log file (pcxboot_l.txt) and the subsequent deletion of the binary chunks. This behavior is indicative of an in-memory Java payload loader pattern used to evade detection.
Detects credential-dumping modules (such as nanodump, hashdump, and lsadump variants) associated with AdaptixC2 framework being invoked or used by the 'mscopilot.exe' process. The rule monitors for command-line arguments indicating credential extraction, unauthorized attempts to open handle to lsass.exe, and access to sensitive registry hives (SAM, Security, LSA) by the suspect process.
Detects the deletion, truncation, or modification of critical PaperCut server logs and application files (server.log, pcxboot_l.txt, .bin files). This activity is associated with attempts to conceal exploitation of PaperCut vulnerabilities (e.g., CVE-2026-82078/81578) by clearing logs or tampering with binaries, typically executed by the PaperCut application processes themselves (pc-app.exe or Java runtime).
This rule detects suspicious activity originating from the PaperCut 'pc-app.exe' process. It monitors for the creation or execution of a file named 'mscopilot.exe' within the non-standard directory 'C:\Microsoft.Office365\'. The rule matches based on a known malicious SHA1 hash or the specific file-write-then-execute behavior within a one-hour window, indicating potential AdaptixC2 loader activity.
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
Detects network traffic associated with Adversary-in-the-Middle (AiTM) phishing kits that impersonate Microsoft and Google login pages. The rules identify the presence of specific HTML elements (like Cloudflare Turnstile anti-bot gates) and authentication session cookie headers served from non-authorized/non-official domains, indicating a reverse-proxy phishing attack.
Detects network traffic associated with Adversary-in-the-Middle (AiTM) phishing kits that impersonate Microsoft and Google login pages. The rules identify the presence of specific HTML elements (like Cloudflare Turnstile anti-bot gates) and authentication session cookie headers served from non-authorized/non-official domains, indicating a reverse-proxy phishing attack.
Detects potential poisoning of an AI agent's RAG knowledge base or vector store through suspicious bulk ingestion or injection of imperative instruction-style content. The rule correlates these ingestion events with subsequent anomalous tool usage patterns by the same agent session, indicating a possible prompt injection or data manipulation attack aimed at altering agent behavior.
Detects potential poisoning of an AI agent's RAG knowledge base or vector store through suspicious bulk ingestion or injection of imperative instruction-style content. The rule correlates these ingestion events with subsequent anomalous tool usage patterns by the same agent session, indicating a possible prompt injection or data manipulation attack aimed at altering agent behavior.
Detects instances where the WMI Provider Host (wmiprvse.exe) spawns suspicious child processes such as cmd.exe, powershell.exe, or rundll32.exe, which are correlated with inbound network connections on ports 135 (RPC/DCOM) or 445 (SMB). This behavior is characteristic of lateral movement techniques used by tools like Impacket's wmiexec.
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (lsass.exe) with sensitive access rights (e.g., PROCESS_VM_READ, PROCESS_QUERY_INFORMATION). These access patterns are frequently utilized by credential dumping tools like Mimikatz, ProcDump, or malicious abuse of system utilities to extract plaintext passwords or NTLM hashes from memory.
Detects the execution of PowerShell or PWSH with encoded command flags (-EncodedCommand, -enc, -e), which is a common technique used by adversaries to hide malicious scripts or payloads from inspection.
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.


