Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects the execution of common remote access and RMM (Remote Monitoring and Management) tools spawned directly from web browser processes (e.g., Chrome, Edge, Firefox). It further monitors for subsequent suspicious child process activity such as command shell execution or file operations performed by these RMM tools, which is a common pattern in post-exploitation and initial access activities.
This rule detects potentially malicious PowerShell, CMD, or PWSH command execution characterized by obfuscation techniques (such as Base64 encoding, decompression, or hidden command arguments) that are followed closely in time by network connections to public AI service domains (OpenAI, Anthropic, Google Generative Language, Mistral, Cohere). The detection correlates process-start events with outbound network requests from processes other than standard web browsers, suggesting potentially unauthorized use of AI APIs for exfiltration or automated processing of command results.
This rule detects the suspicious loading of known vulnerable drivers (Bring Your Own Vulnerable Driver - BYOVD) via the Windows service control manager (sc.exe) or event log 7045, followed by the immediate termination of major endpoint security software processes within a 300-second window. This behavior is indicative of an attempt to disable or tamper with security tools using kernel-level privileges.
Detects suspicious administrative activity involving privileged users performing bulk account/object deletions or stopping critical identity-related services (ADFS, Active Directory Certificate Services). The rule specifically flags events occurring outside standard business hours, involving privileged AD groups, or directly targeting identity infrastructure, indicating a potential attempt to disrupt authentication services or sabotage identity management.
Detects anomalous mass file modification or renaming activity often associated with ransomware, combined with the deletion of Windows Volume Shadow Copies using native utilities like vssadmin or wmic, and the presence of suspicious ransom note filenames.
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
Detects instances where a user account consents to an OAuth application requesting high-privilege or sensitive scopes such as Mail.Read, Files.ReadWrite.All, or offline_access. This behavior is a common indicator of consent phishing attacks, where adversaries trick users into granting persistent access to their cloud resources via malicious OAuth applications.
Detects instances where a user successfully authenticates via the OAuth Device Code flow using an unmanaged or non-compliant device, followed closely by high-privileged Azure/Graph API administrative actions within a short timeframe. This behavior is indicative of a device-code phishing attack aimed at bypassing MFA controls, including FIDO2/passkeys, by compromising an active session.
This rule detects a multi-stage Business Email Compromise (BEC) attack involving executive impersonation via look-alike domains, followed by the creation of suspicious inbox rules (forwarding/deletion) by the victim, and concurrent external communication (Teams/Zoom meeting invites) from a newly created account. It correlates these activities to identify sophisticated payment fraud campaigns.
Detects the installation of browser extensions that utilize sensitive permissions (e.g., full URL access, cookie access) followed shortly by network connections to potentially non-reputable domains within one hour of the installation. This pattern is indicative of malicious browser extensions established for data exfiltration or credential theft.
Detects potential browser-based infostealer activity where a non-standard process, launched from temporary or user-download directories, accesses sensitive browser data files (cookies, login data) followed by a suspicious outbound network connection to a previously unseen domain, matching common patterns for LummaStealer or Vidar malware.
Detects high-risk domain account activity, specifically identifying either impossible-travel authentication patterns in cloud logs or rapid, multi-host interactive authentication fan-out within one hour. These detections are further correlated with subsequent RDP or WinRM session establishment, indicating potential lateral movement or compromise of legitimate accounts.
This rule detects potential process injection or process hollowing attempts by correlating Sysmon Event ID 10 (ProcessAccess) events indicating process memory modification permissions (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) with subsequent Sysmon Event ID 8 (CreateRemoteThread) events targeting the same process. This behavior is indicative of an adversary injecting malicious code into a legitimate host process (e.g., svchost.exe, explorer.exe).
Detects processes querying registry keys or accessing file paths associated with common virtualization and sandbox environments (e.g., VMware, VirtualBox, Hyper-V, Sandboxie). This behavior is often indicative of malware attempting to identify if it is running in an analysis or sandbox environment to evade detection.
Detects attempts to disable, stop, or reconfigure security software (Antivirus, EDR, Endpoint Protection) on Windows endpoints by abusing legitimate administrative utilities such as sc.exe, net.exe, taskkill.exe, wmic.exe, and PowerShell to tamper with service configurations or kill security-related processes.
Detects host-side indicators of potential container escapes and unauthorized access, including mounting sensitive container runtime sockets, executing containers with privileged flags, host namespace sharing, and the use of nsenter to break out of a container context.

