Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
This rule detects network connections and DNS queries directed towards specific malicious domains or domains matching a pattern hosted on pages.dev, a service frequently abused for hosting malicious infrastructure such as phishing pages or command-and-control beacons.
This rule detects network connections and DNS queries directed towards specific malicious domains or domains matching a pattern hosted on pages.dev, a service frequently abused for hosting malicious infrastructure such as phishing pages or command-and-control beacons.
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
This rule monitors DeviceNetworkEvents and DnsEvents for connections to known malicious domains and IP addresses associated with phishing campaigns. It alerts on any network communication or DNS resolution attempt targeting these indicators, providing visibility into potential user interaction with phishing infrastructure.
This rule monitors DeviceNetworkEvents and DnsEvents for connections to known malicious domains and IP addresses associated with phishing campaigns. It alerts on any network communication or DNS resolution attempt targeting these indicators, providing visibility into potential user interaction with phishing infrastructure.
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
This rule monitors DeviceNetworkEvents and DnsEvents for connections to known malicious domains and IP addresses associated with phishing campaigns. It alerts on any network communication or DNS resolution attempt targeting these indicators, providing visibility into potential user interaction with phishing infrastructure.
ChainScript file manager 'files' task: node.exe performing high-volume recursive deletion within masqueraded ChainScript installation paths (drive enumeration, dir listing, file read/write, recursive delete)
Detects when a single process terminates two or more critical security, database, or backup related processes within a short window. This behavior is often associated with adversary attempts to disable security controls or disrupt database operations, commonly observed during the impact phase of an attack or preparatory to data destruction/encryption.
Detects execution of PowerShell commands that utilize hidden window styles and encoded payloads, specifically when the command line or image path references 'WindowsUpdate.log'. This pattern is often used by adversaries to hide malicious scripts and potentially interact with logs in an attempt to masquerade or tamper with Windows Update processes.
Detects the use of native system utilities including wmic, vssadmin, and wbadmin to delete Volume Shadow Copies or the Backup Catalog, as well as the deletion of local snapshots on macOS via tmutil. These actions are common techniques employed by ransomware to prevent system restoration after encryption.
This rule monitors process execution and registry modifications for filenames, process command lines, or registry keys associated with 'truesight.sys' and 'rentdrv2.sys'. These artifacts are typically associated with malicious kernel-mode drivers, such as rootkits, often used for stealth or persistence on Windows systems.
This rule monitors DeviceNetworkEvents for any outbound network connections initiated from Windows devices to the domain 'files.surveillance-online.com', which is associated with malicious activity.
Page 191 of 1871



