Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects potential poisoning of an AI agent's RAG knowledge base or vector store through suspicious bulk ingestion or injection of imperative instruction-style content. The rule correlates these ingestion events with subsequent anomalous tool usage patterns by the same agent session, indicating a possible prompt injection or data manipulation attack aimed at altering agent behavior.
Detects instances where the WMI Provider Host (wmiprvse.exe) spawns suspicious child processes such as cmd.exe, powershell.exe, or rundll32.exe, which are correlated with inbound network connections on ports 135 (RPC/DCOM) or 445 (SMB). This behavior is characteristic of lateral movement techniques used by tools like Impacket's wmiexec.
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (lsass.exe) with sensitive access rights (e.g., PROCESS_VM_READ, PROCESS_QUERY_INFORMATION). These access patterns are frequently utilized by credential dumping tools like Mimikatz, ProcDump, or malicious abuse of system utilities to extract plaintext passwords or NTLM hashes from memory.
Detects the execution of PowerShell or PWSH with encoded command flags (-EncodedCommand, -enc, -e), which is a common technique used by adversaries to hide malicious scripts or payloads from inspection.
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
Detects execution of rundll32.exe or regsvr32.exe with potentially malicious command-line arguments, including references to external URLs, protocol handlers like javascript:, or loading DLLs from user-writable directories (Temp, AppData, Downloads). This behavior is characteristic of Living-off-the-Land (LotL) techniques used to proxy execution and bypass application control or security monitoring.
Detects Windows Event 4662 indicating the use of DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights from a host that is not a known domain controller. This behavior is highly indicative of credential dumping via DCSync, commonly associated with tools like Mimikatz.
Detects potential DNS tunneling activity by monitoring for unusually long DNS query strings (high entropy indicator), frequent usage of TXT or NULL DNS record types, and high query volume directed at a limited number of unique domains from a single host.
This rule detects potential lateral movement via Remote Desktop Protocol (RDP) by identifying a single user account establishing RemoteInteractive (logon type 10) sessions to three or more distinct destination hosts within a 15-minute timeframe. This pattern is indicative of an attacker attempting to traverse a network from a compromised host.
Detects instances where one process initiates an injection mechanism (such as CreateRemoteThread, QueueUserAPC, or NtMapViewOfSection) into another process. The rule specifically alerts when these actions target common, high-value, or frequently abused processes such as explorer.exe, svchost.exe, or web browsers (chrome.exe, firefox.exe, msedge.exe), which are common targets for maintaining persistence or evading detection.
Detects anomalous lateral movement behavior by monitoring Windows Event 4624 (Logon Type 3) using NTLM authentication. The rule triggers when a single user account authenticates to five or more distinct hosts within a five-minute window, a pattern frequently associated with Pass-the-Hash attacks where captured credentials are used to spread across a network.
Detects non-SYSTEM processes enabling SeDebugPrivilege or SeImpersonatePrivilege shortly before launching a process as the SYSTEM user. This behavior is highly indicative of token manipulation and impersonation techniques (e.g., Potato-family exploits) used to elevate privileges from a standard or administrative account to SYSTEM.
Detects high-volume outbound network traffic (exceeding 50MB) directed towards known consumer-grade cloud storage and anonymous file-sharing services. This activity can indicate data exfiltration, as these services are frequently abused to bypass security controls while masking data movement within legitimate-appearing traffic.
Detects attempts to disable security services (Windows Defender, EDR agents), modify audit policies via auditpol, or stop/clear the Windows Event Log service. This behavior is a common precursor to post-compromise activity intended to blind defenders and conceal malicious actions.
Detects instances where a user grants OAuth application permissions to an unverified third-party application. The rule specifically monitors for high-privilege scopes such as Mail.Read, Files.ReadWrite.All, or full_access_as_app, which are commonly abused in illicit consent grant attacks to achieve persistent access to sensitive mailbox and cloud data.
Detects instances where an IAM user creates a new access key or requests a session token, followed by subsequent API activity from a different source IP address or region within a one-hour window. This behavior is often associated with the creation of persistence mechanisms or credential theft.
Detects an attempt to perform Active Directory replication (DS-Replication-Get-Changes or DS-Replication-Get-Changes-All) initiated by a machine that is not a recognized Domain Controller. This is a common indicator of credential dumping or unauthorized domain information gathering.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.

