Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects browser-side network activity involving known command-and-control or subscription API domains associated with a malicious VPN browser extension proxy campaign. The rule monitors for beaconing behavior from popular web browsers (Chrome, Edge, Brave) to specific domains utilized by the campaign.
Detects network traffic attempting to connect to known proxy farm fallback hostnames using TLS SNI or HTTP CONNECT methods. These hostnames are often associated with command-and-control infrastructure designed to proxy traffic and mask the true destination of communications.
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
Flags conditional access policy edits (MFA exclusions, trusted-location additions) occurring shortly after a support-desk-driven identity reset on the same tenant/admin account — the step attackers use to lock in access after a vishing-driven MFA bypass.
Joins password reset events to subsequent legacy-protocol (IMAP/POP/SMTP/ActiveSync) or non-interactive sign-ins for the same user, catching attackers who pivot to less-monitored protocols immediately after a vished self-service reset.
Flags MFA method deletions performed by an actor other than the account owner, especially when followed by registration of a new authenticator — the signature of a helpdesk agent socially engineered into swapping a victim's MFA factor.
Sequence detection for the three-step chain — credential reset, MFA/authenticator reset, new device registration — completing within 40 minutes for one user, directly modeling the Scattered Spider/UNC3944 speed-to-domain-admin playbook from Mandiant M-Trends 2026.
Flags Temporary Access Pass issuance to accounts holding privileged directory roles, especially when issued by Tier-1 support rather than a PIM-approved workflow — TAP is the modern equivalent of the helpdesk MFA bypass abused in Scattered Spider-style intrusions.
Flags FIDO2/passkey registrations initiated or facilitated by a helpdesk/support identity for another user's account, matching Okta's advisory on threat actor O-UNC-066 ('Pink' leak site) and the ShinyHunters O-UNC-037 campaign that mimicked Microsoft's passkey enrollment flow to register attacker-controlled passkeys.
Detects evidence of a SharePoint pre-authentication RCE exploit chain where an adversary injects a malicious Namespace containing an ExpandedWrapper-wrapped XamlServices payload (e.g., ObjectDataProvider or LosFormatter gadget) into the w3wp.exe worker process. This specifically looks for command-line arguments indicative of deserialization-based exploit attempts targeting SharePoint web server components.
This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
Detects anomalous, bulk file access activity targeting browser credential databases, cryptocurrency wallet data, and application-specific configuration stores, characteristic of the SectopRAT 'DeployBrowserKey' command.
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
Detects the execution of RatHat, a Go-based Android native daemon masquerading as 'liblocal-service.so'. The rule identifies the malware's use of ADB-derived shell commands to bypass Android Doze mode, prioritize background execution, and tamper with installed applications via pm (package manager) commands.


