Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools when initiated from suspicious parent processes (such as browsers, office applications, or command-line interpreters), originating from common writeable directories (e.g., Temp, Downloads), or executed with command-line arguments indicative of silent/unattended installation. This behavior is often associated with initial access, persistence establishment, or unauthorized remote control of a system.
This rule detects anomalous, high-volume activity from a single user account interacting with known public generative AI platforms (e.g., ChatGPT, Copilot, Claude). It uses a threshold-based approach on CloudAppEvents logs to identify potential reconnaissance or bulk information gathering activities which could signify unauthorized use or automated data scraping via AI interfaces.
Detects the execution of MSP360 or generic RMM-labeled binaries originating from common user download directories (Downloads or Temp folders) when the filename mimics common phishing lures such as invoice, e-card, RSVP, or document-related naming conventions. This activity indicates a potential social engineering attempt to execute remote monitoring and management tools.
Detects instances where a legitimate Remote Monitoring and Management (RMM) agent (MSP360 or Faronics) is used to execute PowerShell commands that silently install ScreenConnect (ConnectWise Control) MSI packages within a 10-minute window. This behavior is indicative of an adversary abusing administrative tools for lateral movement or persistence.
This rule detects the execution of potentially malicious binaries masquerading as legitimate Windows utilities (e.g., Windows Update, Defender, or Phone Link) from within a ScreenConnect temporary directory. This behavior is indicative of a phishing attack where an adversary uses remote access tools to stage and execute malicious payloads on a victim's system.
This rule detects the execution of potentially malicious binaries masquerading as legitimate Windows utilities (e.g., Windows Update, Defender, or Phone Link) from within a ScreenConnect temporary directory. This behavior is indicative of a phishing attack where an adversary uses remote access tools to stage and execute malicious payloads on a victim's system.
Detects potential persistence and network persistence mechanisms associated with the MSP360 RMM agent. The rule correlates the creation of a Windows service for RMM.Agent.exe or RMM.Agent.Launcher.exe with the addition of a firewall rule allowing UDP traffic on port 48678 by netsh or PowerShell, occurring within a one-hour window.
Detects potential persistence and network persistence mechanisms associated with the MSP360 RMM agent. The rule correlates the creation of a Windows service for RMM.Agent.exe or RMM.Agent.Launcher.exe with the addition of a firewall rule allowing UDP traffic on port 48678 by netsh or PowerShell, occurring within a one-hour window.
This rule monitors for DNS queries and network connections to a known list of malicious domains associated with phishing campaigns that deploy remote access tools (such as ScreenConnect or MSP360). These campaigns typically involve users interacting with malicious links to trigger downloads or remote management sessions.
This rule monitors for DNS queries and network connections to a known list of malicious domains associated with phishing campaigns that deploy remote access tools (such as ScreenConnect or MSP360). These campaigns typically involve users interacting with malicious links to trigger downloads or remote management sessions.
Detects the presence or execution of known malicious Remote Monitoring and Management (RMM) tool binaries associated with phishing campaigns, such as those impersonating MSP360 or ScreenConnect.
Detects the presence or execution of known malicious Remote Monitoring and Management (RMM) tool binaries associated with phishing campaigns, such as those impersonating MSP360 or ScreenConnect.
This rule monitors for DNS queries and network connections to a known list of malicious domains associated with phishing campaigns that deploy remote access tools (such as ScreenConnect or MSP360). These campaigns typically involve users interacting with malicious links to trigger downloads or remote management sessions.
Detects the execution of MSP360 or generic RMM-labeled binaries originating from common user download directories (Downloads or Temp folders) when the filename mimics common phishing lures such as invoice, e-card, RSVP, or document-related naming conventions. This activity indicates a potential social engineering attempt to execute remote monitoring and management tools.
Detects instances where a legitimate Remote Monitoring and Management (RMM) agent (MSP360 or Faronics) is used to execute PowerShell commands that silently install ScreenConnect (ConnectWise Control) MSI packages within a 10-minute window. This behavior is indicative of an adversary abusing administrative tools for lateral movement or persistence.
This rule detects the execution of potentially malicious binaries masquerading as legitimate Windows utilities (e.g., Windows Update, Defender, or Phone Link) from within a ScreenConnect temporary directory. This behavior is indicative of a phishing attack where an adversary uses remote access tools to stage and execute malicious payloads on a victim's system.

