Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
PetitPotam NTLM Coercion via EFSRPC
Cortex XDR
This rule detects the use of EfsRpcOpenFileRaw (opnum 0) against the EFSRPC interface. This specific function is abused by the PetitPotam exploit to coerce a Windows machine, typically a domain controller, into authenticating to an attacker-controlled host via NTLM. This forced authentication is a precursor to NTLM relay attacks such as those targeting Active Directory Certificate Services (AD CS).
Detects potential ClickFix-style social engineering attacks where a victim is prompted to execute an encoded PowerShell command (often via copy-paste into a terminal). The rule specifically monitors PowerShell processes initiated by shell environments (explorer.exe, cmd.exe, or WindowsTerminal.exe) that execute encoded, hidden scripts to perform multiple suspicious network requests for files (e.g., .zip, .enc, .bin) from non-standard domains.
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
Detects evidence of the Rapuncel infostealer attempting to compromise Chrome or Edge browsers. The rule identifies suspicious image loads into browser processes linked to known malicious hashes or the creation of specific browser decryption log files used by the malware to defeat App-Bound encryption.
Detects instances where Microsoft Visual Studio Code (Code.exe) spawns common interpreters or command-line tools (such as node, python, cmd, or powershell) that are not associated with known internal VS Code process behaviors like renderer tasks or tunnel operations. This activity may indicate malicious use of the integrated terminal or extension execution contexts to execute unauthorized code.
Detects the modification of Windows Registry Run keys that point to suspicious executable paths or known naming patterns associated with specific services (SMQDService and winappx) often utilized for persistence.
Detects the creation or modification of registry entries within the 'HKCU\...\Run' hive that point to executables located in suspicious or atypical directories such as 'ProgramData', 'Users\All Users', or specific non-standard application paths often used by malware for persistence.
Detects instances where a desktop messaging application (WhatsApp or Telegram) spawns a child process that matches known suspicious naming conventions or lure keywords, suggesting that a user has executed a malicious file shared via the platform.
Detects the execution of binaries masquerading as legitimate software (such as KeePass, Adobe Flash, or specialized medical document viewers) from user-writable and non-standard execution paths (e.g., Downloads, Temp). This behavior is characteristic of the CHOSEN BRICK malware's lure-execution stage, where users are socially engineered into running a decoy installer.
Detects the use of built-in Windows utilities and commands to disable system recovery features, delete volume shadow copies, clear backup catalogs, or perform mass file deletion. This behavior is highly indicative of wiper malware preparing for a destructive attack by preventing system recovery.
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
Page 179 of 1871


