Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of rundll32.exe with command-line arguments that include references to 'WindowsUpdate.log' and a specific ordinal or function index. This pattern is commonly associated with attempts to leverage rundll32.exe to execute arbitrary code while masquerading as legitimate Windows update operations.
Detects when three or more critical security, database, or service processes are terminated on a Windows host within a short timeframe. This behavior is often indicative of an adversary attempting to disable security monitoring (e.g., Windows Defender/MsMpEng.exe) or perform disruptive activity against critical infrastructure (e.g., SQL Server processes).
Detects the creation, modification, or execution of known malicious files associated with the Kimsuky threat actor, based on a static list of MD5 hashes observed in their campaigns.
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
This rule detects network connections and DNS queries directed towards specific malicious domains or domains matching a pattern hosted on pages.dev, a service frequently abused for hosting malicious infrastructure such as phishing pages or command-and-control beacons.
This rule monitors DeviceNetworkEvents and DnsEvents for any network connection attempts or DNS queries directed towards the known malicious domain 'hyundaiservisiankara.com'. This pattern is indicative of a host attempting to communicate with an external C2 infrastructure.
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
Detects a suspected malicious sequence associated with RatHat activity. The rule identifies a device fetching an injection template configuration from a remote URL, followed by the exfiltration of credentials or form data to specific API endpoints on the same device within a 15-minute window.
This rule detects suspicious activity where a node.exe process, often associated with a node-pty terminal emulation, launches common Windows command-line shells (cmd.exe, powershell.exe) from specific file paths or directories. This behavior is indicative of a Node.js-based Remote Access Trojan (RAT) or shell spawning mechanism being used to establish command and control or persistence on a Windows host.
Detects outbound WebSocket connections from endpoints containing specific JWR phishing framework session tokens (JWRCID/JWRCVV) or known C2 path suffixes. This pattern indicates active communication with a malicious C2 server used for session hijacking or proxy-based phishing operations.
This rule detects when the Node.js runtime process (node.exe) initiates the Windows command interpreter (cmd.exe) with the '/c' flag, which is commonly used to execute commands or scripts. This behavior is frequently associated with malicious Node.js activity, such as Remote Access Trojans (RATs) or web shells, which may use the shell to execute system-level operations or bypass typical application constraints.
Detects processes attempting to open a handle to the Local Security Authority Subsystem Service (LSASS) process with access rights commonly associated with credential dumping. This detection focuses on identifying suspicious cross-process access requests originating from non-standard or non-authorized processes, such as those used by C2 frameworks like OnyxC2 for extracting cached Windows credentials.
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy the Active Directory database file (ntds.dit) from the shadow copy. This pattern is commonly used by adversaries to perform offline credential dumping.
Detects potential exploitation of CVE-2025-3248 in Langflow by identifying suspicious inbound network traffic targeting the /api/v1/validate/code endpoint, correlated with subsequent python child processes containing base64 decoding and execution primitives such as eval, exec, or subprocess.
This rule detects PowerShell processes executing with hidden window styles while performing web-based download operations from GitHub domains. It further identifies potential nested PowerShell execution, which is often used in obfuscated download-and-execute attack chains.
This rule detects the addition or modification of Windows Firewall rules by applications residing in non-standard or suspicious directories. It monitors Security Events 2004, 2071, and 2097, filtering out known legitimate system paths, common temporary directories, and updates from trusted Microsoft processes such as Windows Defender, svchost.exe, and dllhost.exe. By excluding standard operating system folders and common software installation paths, the rule highlights potentially malicious attempts to establish persistence or facilitate unauthorized network communication by bypassing standard firewall management channels.
Detects the execution of specific web browsers (Chrome, Edge, Opera) to facilitate identification of vulnerable browser versions as indicated by CVE-2026-0628 and CVE-2026-55945. This rule does not perform version checking directly but serves as a telemetry trigger for external asset inventory correlation.
Detects in-memory modification of the AmsiScanBuffer function within PowerShell processes, specifically targeting the injection of patch instructions (e.g., MOV EAX, 80070057; RET). This technique is characteristic of .NET loaders like PIVOTPIPE attempting to bypass Antimalware Scan Interface (AMSI) inspection before executing malicious payloads.
Page 192 of 1871




