Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential DLL sideloading activity where legitimate, signed binaries (such as COTFileReadApp.exe or DeElevate64.exe) are executed from non-standard directories (e.g., AppData, Temp, Downloads) while loading specifically identified malicious or sideloaded DLLs. The detection identifies patterns where these binaries operate outside their expected vendor installation paths, indicating a likely attempt to hijack execution flow.
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
This rule monitors for known malicious file hashes, command and control (C2) domains, and specific download URLs associated with identified threats. It correlates these indicators across process execution, file activity, and network connection logs to identify potential compromises or malicious activity related to the aware-cr1 infrastructure.
This rule detects known-malicious activity associated with Warlock ransomware and the ToolShell malware campaign (linked to Storm-2603). It monitors for process, file, and image-load events matching identified malicious file hashes, as well as network connection attempts to known malicious domains and URLs. It also includes monitoring for traffic to 'oastify.com', a domain commonly used for Burp Collaborator, which requires correlation with other indicators to confirm malicious intent.
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
Detects the execution of known cloud synchronization utilities like rclone, megasync, or megacmd, which are frequently leveraged by ransomware operators to exfiltrate data to public cloud storage providers. The rule monitors both local process execution with typical command-line arguments and subsequent outbound network connections to common cloud storage domains.
Detects potential exploitation attempts targeting the vulnerable Oracle PeopleSoft PSEMHUB Environment Management Hub endpoint (associated with CVE-2026-35273 and UNC6240). The rule identifies suspicious bursts of POST requests where the URI path uses percent-encoding or mixed-case characters to evade Web Application Firewall (WAF) filtering.
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
Detects the creation of persistence mechanisms through both Registry Run keys and Scheduled Tasks within a one-hour window, specifically targeting names indicative of masquerading as legitimate update or helper components.
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
Page 18 of 1866



