Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects Kerberos ticket requests (AS-REQ/TGS-REQ) that exhibit characteristics of a forged Golden Ticket, specifically the use of legacy RC4 (0x17) encryption in environments where AES is typically preferred, non-standard ticket options (0x40810000), and requests for accounts or services that lack a corresponding legitimate authentication event. This detection aims to identify the post-compromise phase where an adversary uses a forged TGT to impersonate domain accounts.
Detects the use of native Windows utilities such as vssadmin, ntdsutil, or diskshadow to create volume shadow copies for the purpose of accessing or extracting the ntds.dit Active Directory database file. This activity is a common indicator of credential theft attempts where adversaries bypass file access protections to offline-process the database and retrieve password hashes.
Detects unauthorized access attempts to SYSTEM-level processes (winlogon.exe, services.exe) using specific access rights such as PROCESS_DUP_HANDLE or PROCESS_QUERY_INFORMATION. This behavior is indicative of token stealing or impersonation attempts often utilized by tools like JuicyPotato, RoguePotato, and PrintSpoofer to escalate privileges to SYSTEM.
Detects a sequence of multiple RDP authentication failures (Event ID 4625, Logon Type 10) from a specific source IP, followed by a successful RDP authentication (Event ID 4624, Logon Type 10) from the same source IP. This pattern indicates a successful credential brute force or password spraying attack against RDP, which is a common initial access vector for ransomware and lateral movement.
Detects potential process injection attempts where a browser or Office application attempts to write to the memory or create a remote thread within high-value or trusted system processes like svchost.exe or explorer.exe. This activity is indicative of defense evasion techniques such as DLL or PE injection.
Detects suspicious process access to the Local Security Authority Subsystem Service (lsass.exe) with access masks commonly associated with credential dumping techniques. The rule specifically monitors for high-privileged access requests by unauthorized processes, excluding known legitimate tools and system services, to identify attempts to extract cached authentication materials such as NTLM hashes or Kerberos tickets.
This rule detects PowerShell processes (including pwsh and ISE) referencing Anti-Malware Scan Interface (AMSI) related classes and methods in their command line arguments. This is a common indicator of an attempt to interact with or manipulate AMSI, often used to bypass or disable security scanning during the execution of malicious scripts.
Detects the creation or connection of named pipes that match known default and common malleable C2 profile patterns used by the Cobalt Strike post-exploitation framework. These named pipes are frequently utilized by Cobalt Strike beacons for inter-process communication, SMB/TCP beacon functionality, and staging during post-exploitation activities.
This rule detects PowerShell processes (including pwsh and ISE) referencing Anti-Malware Scan Interface (AMSI) related classes and methods in their command line arguments. This is a common indicator of an attempt to interact with or manipulate AMSI, often used to bypass or disable security scanning during the execution of malicious scripts.
Detects instances where the WMI service (wmiprvse.exe) spawns common command-line or system tools such as cmd.exe, powershell.exe, or rundll32.exe. This behavior is often indicative of lateral movement or remote command execution via WMI.
Detects common suspicious PowerShell command-line patterns often used for malicious purposes, including base64-encoded command execution, hidden-window execution with common evasion flags, and the use of download/execution cmdlets for in-memory payload delivery.
This rule detects potential lateral movement by identifying a single user account authenticating to three or more distinct hosts using NTLM via network (LogonType 3) or impersonation (LogonType 9) logons, which is characteristic of credential-based movement across a network.
This rule monitors for an abnormally high number of Kerberos Ticket Granting Service (TGS) requests using the RC4-HMAC encryption type (0x17) from a single IP address to various service accounts. This pattern is indicative of Kerberoasting, a technique where attackers attempt to obtain service tickets to crack service account passwords offline.
This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys that point to executables or scripts located within suspicious user-writable directories such as AppData, Temp, or Users Public. This is a common technique used by adversaries to establish persistence on a compromised host.
Detects attempts to disable, modify, or stop security software and endpoint protection services. The rule monitors for registry changes to Windows Defender settings, manual service management commands (sc, net) targeting security processes, and PowerShell execution using 'Set-MpPreference' to disable protection features.
Detects instances where a process attempts to access the memory of the Local Security Authority Subsystem Service (LSASS.exe) with suspicious access rights often associated with credential dumping. The rule excludes known benign processes such as antivirus and debugging tools.
Detects Kerberos TGS requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting. By monitoring Event IDs 4768 and 4769 for this specific encryption type, this rule identifies potential attempts to offline-crack service account passwords.
Detects the execution of known Windows system binaries (rundll32, regsvr32, mshta, msiexec) with command-line arguments indicative of proxy execution or script-based attacks. The rule identifies patterns commonly associated with downloading or executing remote payloads, including the use of URLs, JavaScript, VBScript, or specific DLL exports designed to execute code indirectly or from a remote source.
Detects Microsoft Office applications (Word, Excel, Outlook, PowerPoint) spawning common LOLBins or command-line interpreters. This behavior is frequently associated with malicious macros or exploitation attempts delivering secondary payloads.
Detects the creation or modification of scheduled tasks that exhibit suspicious characteristics, such as using common temporary directories, executing PowerShell with encoded commands, running tasks as SYSTEM, or using tasks that attempt to hide by using unusual naming conventions. These techniques are often used by adversaries to establish persistence or facilitate execution in a stealthy manner.
Detects anomalous DNS queries that utilize long labels or non-standard record types (TXT, NULL, CNAME) which are frequently associated with DNS tunneling and command-and-control communication. The rule flags endpoints with a high volume of these suspicious requests or exceptionally long domain labels.
