Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects HTTP requests to the OnyxC2 backend API sync endpoint (akmuniverstall.top) carrying the characteristic hwid, ownertoken, and botversion=3.0 parameters used for device-fingerprint C2 check-ins.
Detects a low-level keyboard hook or screen-capture API call from an unsigned, non-standard-path process, correlated with periodic image/keystroke buffer file staging, consistent with OnyxC2's premium keylogger/screenshot module.
Correlates the ShieldBreak PoC's 'Exploit succeeded' console output with a SYSTEM-privileged cmd.exe spawn in the same process session within a short window, confirming successful end-to-end exploitation of CVE-2026-50656.
Detects JWR phishing framework client engine script via known SHA256 hashes (standalone high-confidence), or the co-occurrence of anti-debug check, staging path structure, and Simplified Chinese operator status strings
Correlates DNS/network requests to newly observed domains matching JWR's brand-plus-suffix generation pattern across .top/.cfd/.info/.cc TLDs, requiring multiple distinct hostnames sharing the same brand token within a short window to flag likely batch-registered phishing infrastructure.
Detects the hard-coded RC4 key fragment used by BTR.sys to decrypt its transaction structure when co-located within 0x4000 bytes of the FEE1DEAD magic value and Version 2 header field, targeting the encrypted transaction/ADS payload content independent of driver binary version.
Detects suspicious Active Directory Replication Service (ADRS) requests originating from
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.
Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.
Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
Detects additions to privileged groups (e.g. Domain Admins) or modification of password-change-policy flags on a previously dormant account being reactivated, excluding changes linked to an approved change-management ticket and weighting more heavily for off-hours or non-standard admin workstation origin.
Detects creation of a scheduled task named 'IntelSoftwareUpdater' via schtasks.exe that launches pythonw.exe with run.pyw, used by the UNC5142 DeviceManager RAT for persistence, relaunching every 10 minutes.
Detects TLS sessions to Sapphire Sleet/UNC1069 Hostwinds C2 infrastructure presenting the exact self-signed certificate issuer string linked to the Mastra/axios campaigns.
This rule detects network communication attempts (connection success, request, or failure, or any traffic on port 443) targeting a specific malicious domain (notepadreleased.com) or IP address (85.158.110.78), while explicitly excluding common public DNS providers.
Detects a non-system process causing creation of CldFlt0.etl under C:\Windows\System32\LogFiles\CloudFiles\.
This path is initialised by the CldFlt driver when a process calls CfRegisterSyncRoot() or CfConnectSyncRoot().
In the RedSun exploit this is a side-effect of the DoCloudStuff() function that registers a fake sync provider to create the cloud-tagged bait file.
Legitimate cloud providers (OneDrive etc.) register sync roots from SYSTEM-level service processes, not from user-context executables.
This path is initialised by the CldFlt driver when a process calls CfRegisterSyncRoot() or CfConnectSyncRoot().
In the RedSun exploit this is a side-effect of the DoCloudStuff() function that registers a fake sync provider to create the cloud-tagged bait file.
Legitimate cloud providers (OneDrive etc.) register sync roots from SYSTEM-level service processes, not from user-context executables.
This rule detects potentially malicious attempts to modify Windows process protection levels, often used by attackers employing Bring Your Own Vulnerable Driver (BYOVD) techniques. It identifies when processes use command-line arguments like 'PsProtectedSignerAntimalware' or 'SetProcessMitigationPolicy' to assign elevated protection levels, while simultaneously ensuring the initiating process is either unsigned or not a standard executable file, which is highly indicative of suspicious activity.
This rule detects command-line activity that references sensitive Windows API functions or privileges associated with token manipulation and process privilege escalation, such as SeDebugPrivilege, SeImpersonatePrivilege, DuplicateTokenEx, CreateProcessWithTokenW, and NtSetInformationToken. The rule excludes common service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to focus on potentially unauthorized use by standard or administrative accounts.
This rule monitors for two critical firmware-related conditions: detected non-compliance with secure boot, UEFI, or TPM configuration standards via Microsoft Defender TVM, and explicit firmware or boot configuration change events reported by device telemetry. It is designed to identify potential tampering or misconfigurations that could facilitate bootkits or other pre-OS persistence mechanisms.
This rule identifies network connections using deprecated, insecure TLS versions (TLS 1.0, 1.1) or weak cipher suites (RC4, 3DES, NULL). The use of these legacy cryptographic protocols is a security risk, as they are vulnerable to various attacks like man-in-the-middle, and may indicate misconfigured servers, legacy infrastructure, or attempts by an adversary to downgrade encryption to facilitate traffic interception or inspection.
Detects the installation of a Manifest V3 browser extension that requests the 'chrome.proxy' permission as its sole permission. This behavior is indicative of potential malicious extensions designed to modify web traffic or route browser activity through an adversary-controlled proxy server.
This rule detects attempts to disable, stop, or uninstall various security products, including antivirus and EDR solutions, by monitoring command-line activity for administrative utilities like sc.exe, net.exe, wmic.exe, and PowerShell.
This rule detects scenarios where a new user account is created (Event ID 4720) and is subsequently logged into (Event ID 4624) within a 30-minute window. This behavior can indicate an adversary creating a backdoor or service account for persistence or lateral movement, followed by immediate usage of that account.
Detects execution of the SimpleChatProxy/'Chat Proxy' tool correlated with outbound traffic to an attacker-hosted image endpoint, used for operator-victim messaging and remote screenshot retrieval.
Detects an unsigned Loader.exe spawning a second unsigned executable that performs immediate outbound network fetch, matching the StopAndProtect loader/downloader chain with sandbox-evasion checks.
Page 476 of 1870



