Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
Detects a suspicious pattern where an AI coding agent or user creates a public GitHub repository with specific naming conventions (e.g., 'sweeper-demo', 'gitshot-images') and subsequently pushes content containing sensitive terms like 'screenshot' within a short timeframe. This behavior is indicative of potential data exfiltration of internal development screenshots to a public repository.
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
Detects sign-in attempts originating from IP address ranges known to be utilized by the TeamFiltration tool for password spraying operations against Azure environments.
Detects HTTP POST requests directed at Grav CMS endpoints where the __unique_form_id__ parameter contains directory traversal sequences (e.g., ../). This behavior is indicative of attempted exploitation of CVE-2026-42608, aimed at bypassing file system restrictions to write files to unauthorized locations outside the application's expected form data directory.
Detects HTTP POST requests directed at Grav CMS endpoints where the __unique_form_id__ parameter contains directory traversal sequences (e.g., ../). This behavior is indicative of attempted exploitation of CVE-2026-42608, aimed at bypassing file system restrictions to write files to unauthorized locations outside the application's expected form data directory.
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
This rule detects malicious HTTP POST requests attempting a path traversal attack against Grav CMS, specifically targeting the __unique_form_id__ parameter. The rule looks for directory traversal sequences ('..') following the parameter, which is characteristic of attempts to read sensitive files outside the intended web directory.
This rule detects malicious HTTP POST requests attempting a path traversal attack against Grav CMS, specifically targeting the __unique_form_id__ parameter. The rule looks for directory traversal sequences ('..') following the parameter, which is characteristic of attempts to read sensitive files outside the intended web directory.
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string

