Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys that point to executables or scripts located within suspicious user-writable directories such as AppData, Temp, or Users Public. This is a common technique used by adversaries to establish persistence on a compromised host.
Detects attempts to disable, modify, or stop security software and endpoint protection services. The rule monitors for registry changes to Windows Defender settings, manual service management commands (sc, net) targeting security processes, and PowerShell execution using 'Set-MpPreference' to disable protection features.
Detects instances where a process attempts to access the memory of the Local Security Authority Subsystem Service (LSASS.exe) with suspicious access rights often associated with credential dumping. The rule excludes known benign processes such as antivirus and debugging tools.
Detects Kerberos TGS requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting. By monitoring Event IDs 4768 and 4769 for this specific encryption type, this rule identifies potential attempts to offline-crack service account passwords.
Detects the execution of known Windows system binaries (rundll32, regsvr32, mshta, msiexec) with command-line arguments indicative of proxy execution or script-based attacks. The rule identifies patterns commonly associated with downloading or executing remote payloads, including the use of URLs, JavaScript, VBScript, or specific DLL exports designed to execute code indirectly or from a remote source.
Detects Microsoft Office applications (Word, Excel, Outlook, PowerPoint) spawning common LOLBins or command-line interpreters. This behavior is frequently associated with malicious macros or exploitation attempts delivering secondary payloads.
Detects the creation or modification of scheduled tasks that exhibit suspicious characteristics, such as using common temporary directories, executing PowerShell with encoded commands, running tasks as SYSTEM, or using tasks that attempt to hide by using unusual naming conventions. These techniques are often used by adversaries to establish persistence or facilitate execution in a stealthy manner.
Detects anomalous DNS queries that utilize long labels or non-standard record types (TXT, NULL, CNAME) which are frequently associated with DNS tunneling and command-and-control communication. The rule flags endpoints with a high volume of these suspicious requests or exceptionally long domain labels.
Detects the invocation of Active Directory replication rights by monitoring Event 4662 for specific directory service replication GUIDs (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All). This behavior is characteristic of adversary techniques such as DCSync used by tools like Mimikatz lsadump::dcsync or Impacket secretsdump to extract domain password hashes.
Detects potential C2 beaconing activity by identifying repeated network connections to the same external host that exhibit consistent payload sizes (low variance) and frequency, or by flagging HTTP requests containing default URI patterns associated with Cobalt Strike profiles.
This rule detects a credential-based attack where a single source IP performs multiple failed RDP (LogonType 3/10) attempts against various user accounts, followed by a successful authentication from the same source within an hour. This pattern is indicative of password spraying or brute-forcing followed by successful lateral movement via Remote Desktop.
Detects Sysmon Event ID 10 (ProcessAccess) events where a process opens lsass.exe with a GrantedAccess mask matching known credential-dumping access rights (e.g. PROCESS_VM_READ combinations used by Mimikatz/ProcDump-style tooling), excluding common legitimate EDR/AV/diagnostic source processes.
This rule monitors for process creation events where the parent process is identified as the WMI Provider Host (wmiprvse.exe) or the Windows Management Instrumentation Command-line (wmic.exe) tool, executing a Win32_Process creation command. This pattern is commonly used by adversaries for remote execution and lateral movement.
Detects potential Kerberoasting activity by identifying anomalous behavior where a single account requests 5 or more unique Kerberos Service Principal Name (SPN) tickets within a 5-minute window, excluding common service accounts and krbtgt ticket requests. This behavior is indicative of an attacker attempting to enumerate and obtain tickets for multiple services for offline brute-force password cracking.
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in PowerShell by monitoring for common bypass techniques such as reflective loading of AmsiUtils, tampering with the amsiInitFailed field, or memory patching of AmsiScanBuffer via Script Block Logging (EventID 4104).
Detects unauthorized Active Directory replication requests (DCSync) by monitoring Event ID 4662 for specific directory replication GUIDs originating from computers not identified as domain controllers or by accounts not pre-approved for replication tasks.
Detects the creation of scheduled tasks using schtasks.exe or Event ID 4698 that involve scripting interpreters (powershell, wscript, mshta, cmd) and suspicious command line arguments often associated with malicious activity, such as encoded commands, hidden windows, or network resource access, specifically when executing under the SYSTEM account context.
Detects the abuse of common Windows LOLBins (Living Off the Land Binaries) like regsvr32, mshta, certutil, and rundll32 to proxy the execution of remote scripts, DLLs, or malicious payloads, a technique often used to bypass security controls.
Detects the creation or modification of Windows Registry Run or RunOnce keys where the associated file path points to suspicious directories (e.g., Temp, AppData, ProgramData, Users\Public) or utilizes living-off-the-land binaries (rundll32.exe, regsvr32.exe) residing outside of the protected System32 directory.
Detects the execution of PowerShell with suspicious command-line flags (EncodedCommand, NoProfile, WindowStyle Hidden, ExecutionPolicy Bypass) combined with either potential Base64-encoded payloads or network-based download cradles (e.g., Invoke-Expression, WebClient).
Detects the use of built-in Windows utilities (vssadmin, wmic, powershell, wbadmin, and bcdedit) to delete volume shadow copies, backup catalogs, or modify boot configuration to prevent system recovery. This activity is commonly associated with ransomware operations to inhibit data restoration.
