Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
Detects SQL injection exploitation attempts against MOVEit Transfer targeting the CVE-2023-34362 vulnerability, followed by the deployment and subsequent interaction with the 'human2.aspx' webshell associated with Cl0p ransomware mass-exploitation campaigns.
Detects MFA-fatigue style attacks (push-bombing) against Microsoft 365 accounts. The rule identifies a pattern where a user experiences a high frequency of MFA challenges or denials (at least 5 within a 10-minute window) immediately followed by a successful sign-in from a previously unseen IP and device, excluding phishing-resistant authentication methods and break-glass accounts.
Detects MFA-fatigue style attacks (push-bombing) against Microsoft 365 accounts. The rule identifies a pattern where a user experiences a high frequency of MFA challenges or denials (at least 5 within a 10-minute window) immediately followed by a successful sign-in from a previously unseen IP and device, excluding phishing-resistant authentication methods and break-glass accounts.
Detects the UAT-11587 TestAssembly.dll downloader by its shared AssemblyAttribute GUID b2b3adb0-1669-4b94-86cb-6dd682ddbea3 embedded in .NET metadata across all campaign builds
Detects Antino backdoor binaries (slc.dll and standalone) via embedded AntinoApp application manifest string and Rust PDB path patterns matching GitHub Actions Windows runner structure.
Detects UAT-11587 diplomatic-lure LNK file exploiting ZDI-CAN-25373 whitespace padding to conceal a PowerShell command that extracts CanonStager (cnmpaui.exe/dll) from TAR archives into %TEMP%
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.

