Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
Detects the execution of 'vsdbg.exe' or 'vsdbg.dll' from locations outside of the legitimate Microsoft Visual Studio installation directories. This behavior is indicative of potentially malicious usage of the Visual Studio debugger components for process injection or evasion.
Detects the loading of 'clr.dll' and 'System.Management.Automation.dll' (or related variants) by a process that is not a known PowerShell host. This behavior is indicative of a 'PSInline' execution technique, where an attacker leverages COM or direct assembly loading to execute PowerShell scripts or commands within a benign or malicious process to avoid spawning explicit powershell.exe processes.
Detects the loading or execution of known SloppyRAT DLL samples. This malware is identified for its implementation of Hell's Gate-style indirect syscalls, utilizing techniques such as DJB2 API hashing and NTDLL stub parsing to evade EDR hooks. The rule monitors for specific file hashes and potential masquerading behaviors (e.g., hostfxr.dll) across image loading, file, and process events.
Detects anomalous network connections initiated by a node.exe process spawned by npm.exe within 2 minutes of a lifecycle script (preinstall or postinstall) execution. This behavior is indicative of malicious dependency installation where a compromised package attempts to exfiltrate data or fetch additional payloads immediately upon installation.
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
Detects the creation of a scheduled task containing the string 'Google Chrome Update' in the command line, where the task is not the legitimate 'GoogleUpdateTaskMachine' task. The rule specifically targets tasks that execute PowerShell or arbitrary executables, which is a common persistence technique used by adversaries to mask malicious tasks as legitimate software updates.
Page 197 of 1871


