Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects potential HTML smuggling activity by identifying a browser process writing an executable file named 'config.exe' to the user's Downloads folder without a traditional network download event, followed immediately by Microsoft Defender SmartScreen or Antivirus reporting a warning or scan failure on the file. This behavior is indicative of a payload being reconstructed on the client-side via JavaScript blobs or data URLs, which is a common characteristic of HTML smuggling delivery chains.
Detects HTTP GET requests to Cloudflare Pages subdomains (.pages.dev) ending in '/File_download', often used as a distribution point for malicious HTA (HTML Application) or WSF (Windows Script File) payloads in spearphishing campaigns.
Detects UAT-11587 Stage 1 HTA and WSF stager template: hidden/zero-sized window, fixed Cloudflare Pages tracking beacon with ?track, and WinHttp/MSXML ActiveXObject loading Stage 2 from Cloudflare R2 or CloudFront.
Detects an authentication pattern characteristic of credential compromise, consisting of a burst of failed authentication attempts against an account within a short window, followed immediately by a successful sign-in from an anomalous or new device/location. This pattern is indicative of brute-force or credential spraying followed by successful validation and potential lateral movement.
Detects an authentication pattern characteristic of credential compromise, consisting of a burst of failed authentication attempts against an account within a short window, followed immediately by a successful sign-in from an anomalous or new device/location. This pattern is indicative of brute-force or credential spraying followed by successful validation and potential lateral movement.
Detects an authentication pattern characteristic of credential compromise, consisting of a burst of failed authentication attempts against an account within a short window, followed immediately by a successful sign-in from an anomalous or new device/location. This pattern is indicative of brute-force or credential spraying followed by successful validation and potential lateral movement.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a multi-stage attack chain originating with a healthcare-themed phishing email (e.g., billing or patient coordination lures) that leads to a link click, followed by a subsequent suspicious user sign-in from a non-managed/non-compliant device for the same recipient. This correlates email threat data, URL click telemetry, and sign-in logs to identify potential credential harvesting.
Detects a multi-stage attack chain originating with a healthcare-themed phishing email (e.g., billing or patient coordination lures) that leads to a link click, followed by a subsequent suspicious user sign-in from a non-managed/non-compliant device for the same recipient. This correlates email threat data, URL click telemetry, and sign-in logs to identify potential credential harvesting.
Detects a multi-stage attack chain originating with a healthcare-themed phishing email (e.g., billing or patient coordination lures) that leads to a link click, followed by a subsequent suspicious user sign-in from a non-managed/non-compliant device for the same recipient. This correlates email threat data, URL click telemetry, and sign-in logs to identify potential credential harvesting.
Detects a multi-stage attack chain originating with a healthcare-themed phishing email (e.g., billing or patient coordination lures) that leads to a link click, followed by a subsequent suspicious user sign-in from a non-managed/non-compliant device for the same recipient. This correlates email threat data, URL click telemetry, and sign-in logs to identify potential credential harvesting.
Detects Heartbleed (CVE-2014-0160) exploitation attempts by monitoring for malformed TLS heartbeat requests (undersized payload) followed by oversized responses from the server that indicate potential memory disclosure.
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.

