Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects suspicious cross-process access (Sysmon Event ID 10) and remote thread creation (Sysmon Event ID 8) targeting sensitive processes such as lsass.exe, svchost.exe, and explorer.exe, which are indicative of process injection or hollowing techniques used for evasion or persistence.
Detects bulk or repeated attempts to stop security-related services and processes (such as EDR or AV agents) or modification of Windows Defender registry keys. This behavior is indicative of a pre-encryption phase in ransomware attacks where adversaries attempt to neutralize endpoint defenses.
Detects suspicious mobile-device HTTP traffic patterns indicative of 'quishing' (QR code phishing). The rule identifies mobile HTTP GET requests (iPhone, Android, Mobile Safari, iPad) that lack a Referer header, followed by HTTP POST requests to common credential entry URI patterns (e.g., /login, /signin) over the same protocol, which is a behavioral indicator of a user being redirected from a scanned QR code to a malicious phishing landing page.
Detects the use of legitimate data-transfer utilities (rclone, MEGA client, restic, WinSCP) configured to exfiltrate data to cloud storage providers. This behavior is identified as a precursor to double-extortion ransomware attacks, where attackers steal sensitive data before encrypting it.
Detects the execution of PowerShell or MSHTA from explorer.exe with command line arguments indicative of malicious activity, such as hidden windows, Base64 encoding, or command execution (IEX/Invoke-Expression). This behavior is common in fileless malware delivery and script-based initial access.
This rule detects the execution of the Cloudflare 'cloudflared' utility from non-standard directory locations. Cloudflared is often abused by threat actors to establish reverse tunnels (e.g., TryCloudflare) to gain unauthorized, persistent, and encrypted external access to a compromised host, effectively bypassing standard perimeter network security controls.
This rule detects instances where common system processes (svchost.exe, explorer.exe, dllhost.exe) perform process injection activities, followed within a 5-minute window by a network connection to known SaaS and collaborative platforms (Slack, Discord, Dropbox, Trello). This combination is often indicative of malicious code executing within a trusted process to facilitate command and control or data exfiltration.
This rule detects the execution of common remote access and RMM (Remote Monitoring and Management) tools spawned directly from web browser processes (e.g., Chrome, Edge, Firefox). It further monitors for subsequent suspicious child process activity such as command shell execution or file operations performed by these RMM tools, which is a common pattern in post-exploitation and initial access activities.
This rule detects potentially malicious PowerShell, CMD, or PWSH command execution characterized by obfuscation techniques (such as Base64 encoding, decompression, or hidden command arguments) that are followed closely in time by network connections to public AI service domains (OpenAI, Anthropic, Google Generative Language, Mistral, Cohere). The detection correlates process-start events with outbound network requests from processes other than standard web browsers, suggesting potentially unauthorized use of AI APIs for exfiltration or automated processing of command results.
This rule detects the suspicious loading of known vulnerable drivers (Bring Your Own Vulnerable Driver - BYOVD) via the Windows service control manager (sc.exe) or event log 7045, followed by the immediate termination of major endpoint security software processes within a 300-second window. This behavior is indicative of an attempt to disable or tamper with security tools using kernel-level privileges.
Detects suspicious administrative activity involving privileged users performing bulk account/object deletions or stopping critical identity-related services (ADFS, Active Directory Certificate Services). The rule specifically flags events occurring outside standard business hours, involving privileged AD groups, or directly targeting identity infrastructure, indicating a potential attempt to disrupt authentication services or sabotage identity management.
Detects anomalous mass file modification or renaming activity often associated with ransomware, combined with the deletion of Windows Volume Shadow Copies using native utilities like vssadmin or wmic, and the presence of suspicious ransom note filenames.
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
Detects instances where a user account consents to an OAuth application requesting high-privilege or sensitive scopes such as Mail.Read, Files.ReadWrite.All, or offline_access. This behavior is a common indicator of consent phishing attacks, where adversaries trick users into granting persistent access to their cloud resources via malicious OAuth applications.
Detects instances where a user successfully authenticates via the OAuth Device Code flow using an unmanaged or non-compliant device, followed closely by high-privileged Azure/Graph API administrative actions within a short timeframe. This behavior is indicative of a device-code phishing attack aimed at bypassing MFA controls, including FIDO2/passkeys, by compromising an active session.
This rule detects a multi-stage Business Email Compromise (BEC) attack involving executive impersonation via look-alike domains, followed by the creation of suspicious inbox rules (forwarding/deletion) by the victim, and concurrent external communication (Teams/Zoom meeting invites) from a newly created account. It correlates these activities to identify sophisticated payment fraud campaigns.

