Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects an attempt to perform Active Directory replication (DS-Replication-Get-Changes or DS-Replication-Get-Changes-All) initiated by a machine that is not a recognized Domain Controller. This is a common indicator of credential dumping or unauthorized domain information gathering.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
This rule detects the creation of scheduled tasks using either 'schtasks.exe' or PowerShell ('powershell.exe', 'pwsh.exe') with suspicious parameters. It flags tasks created in temporary directories (e.g., AppData, Temp, ProgramData, Windows\Temp) or tasks executed with 'highest' privileges or hidden configurations, often used for persistence or lateral movement.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
Detects attempts to dump credentials from the Local Security Authority Subsystem Service (LSASS) process memory using common tools like Mimikatz, Procdump, or built-in system utilities such as comsvcs.dll or command-line arguments indicating memory dump operations.
Detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos TGS requests (Event ID 4769) for tickets encrypted with RC4 (0x17) within a short timeframe. The rule tracks the count of requests and the diversity of Service Principal Names (SPNs) requested by a specific user account, excluding machine accounts.
Detects potential persistence mechanisms on Windows systems by monitoring for the creation or modification of Registry 'Run' or 'RunOnce' keys, as well as the creation of files within the Windows Startup folder. These actions are commonly used by adversaries to ensure malicious code executes automatically upon user login or system startup.
Detects execution of regsvr32.exe with command-line arguments that include a remote URL ('/i:http...') combined with silent, unregistered, and notification-free execution flags ('/s', '/u', '/n'). This behavior is characteristic of the 'Squiblydoo' technique, where attackers use Regsvr32 to execute arbitrary scriptlets from remote servers to bypass application whitelisting.
Detects instances of rundll32.exe being used with suspicious command line arguments, such as referencing JavaScript, loading Control Panel applets (.cpl) via shell32.dll from non-standard locations, or executing DLLs directly from user-writable directories (Temp, AppData, Downloads, ProgramData). These patterns are common techniques used by adversaries to proxy execution and evade detection.
Detects potential lateral movement and persistence activities by identifying suspicious Windows service installations via event ID 7045. The rule flags services with suspicious names or paths (e.g., Temp folders, Public directory) and correlates them with incoming SMB connections (port 445) or services spawned directly by services.exe from suspicious locations, aggregated by host and remote IP.
Detects the execution of the Microsoft HTML Application host (mshta.exe) when it is used to launch scripts from remote URLs (http/https/ftp) or when it spawns common command-line shells and scripting engines, which is a common indicator of living-off-the-land techniques used to execute malicious payloads.
This rule detects various forms of process injection (Remote Thread, APC, Map View of Section) targeting common, high-value Windows processes such as explorer.exe, lsass.exe, and web browsers. This behavior is a common technique used by attackers to gain persistence, elevate privileges, or execute code within the context of legitimate system or user-level processes to evade detection.
Detects modifications to AWS IAM policies (user or role policies) that grant AdministratorAccess, PowerUserAccess, or wildcard permissions (*). This is a common indicator of privilege escalation or persistence, where an attacker grants themselves or another identity broad administrative access within the AWS account.
Detects unauthorized attempts by processes to access the memory of sensitive Windows system processes, specifically LSASS.exe or winlogon.exe, using suspicious access masks associated with memory dumping or credential harvesting.
Detects potential DNS tunneling or Command and Control (C2) activity by analyzing DNS query patterns. The rule identifies anomalous behavior based on high query volume, excessive unique subdomain fanout to a single parent domain, and unusually long average query lengths. This combination is often indicative of data exfiltration or communication with a C2 server over the DNS protocol.
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
Detects the abuse of signed Windows system binaries regsvr32.exe and rundll32.exe for proxy execution, defense evasion, and credential access. The rule identifies suspicious command-line patterns including Squiblydoo (regsvr32 with remote scriptlets), rundll32 executing JavaScript via mshtml.dll, rundll32 performing LSASS credential dumping via comsvcs.dll, and the loading of DLLs from untrusted user-writable locations like Temp or Downloads folders.
Detects Kerberos service ticket requests (EventID 4769) that utilize RC4 encryption (0x17) instead of the more secure AES encryption. Attackers often force RC4-HMAC when requesting service tickets for accounts with Service Principal Names (SPNs) because these tickets are susceptible to offline brute-force attacks to recover service account passwords. This technique is a common precursor to lateral movement and privilege escalation in Active Directory environments.
Detects potential Pass-the-Hash (PtH) activity by monitoring for NTLM network logons (Logon Type 3) that are associated with a blank WorkstationName, often indicating spoofing. This pattern is correlated with the assignment of special privileges (EventID 4672) to capture scenarios where stolen NTLM hashes are replayed for lateral movement into a system.

