Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule monitors endpoint telemetry (DNS queries, network connections, file creation, and process execution) to identify matches against a predefined list of known malicious indicators, including IP addresses, domains, and file hashes (SHA256). The rule differentiates between confirmed malicious activity and low-confidence indicators, providing a prioritized view of potential threats.
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
Detects anomalous process execution and loopback network activity associated with the Model Context Protocol (MCP) 'exec_in_session' method. This pattern indicates an adversary potentially abusing the AI coding assistant's MCP server capabilities to execute arbitrary commands as a C2 channel.
The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute.
Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
This rule detects potential persistence attempts by monitoring for the creation of suspicious registry values (common autostart locations) or new files in the Windows Startup directory. It flags registry value data or file names that match known suspicious patterns (e.g., PowerShell, cmd, temp/appdata paths, URLs) when executed by processes other than trusted installers.
Detects indicators associated with the ChatGPT Custom GPT ClickFix campaign across process, network connection, DNS, and HTTP telemetry: known malicious file hashes, C2 IP addresses, the chattypetty.com domain, and known payload-hosting URLs.
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
This rule detects successful network connections to known malicious IP addresses or the domain 'forgitlab.com', which are associated with the Azazel malware threat infrastructure.
This rule monitors endpoint telemetry (DNS queries, network connections, file creation, and process execution) to identify matches against a predefined list of known malicious indicators, including IP addresses, domains, and file hashes (SHA256). The rule differentiates between confirmed malicious activity and low-confidence indicators, providing a prioritized view of potential threats.
This rule monitors endpoint telemetry (DNS queries, network connections, file creation, and process execution) to identify matches against a predefined list of known malicious indicators, including IP addresses, domains, and file hashes (SHA256). The rule differentiates between confirmed malicious activity and low-confidence indicators, providing a prioritized view of potential threats.
Detects a suspicious two-stage browser activity sequence where a user accesses a Maze survey-builder lure (t.maze.co) followed by a navigation to a Cloudflare Workers subdomain hosting a spoofed Microsoft Authentication device-code phishing page. This pattern is indicative of a multi-stage phishing attack aimed at credential or device token theft.
Detects the Akira ransomware binary staged as C:\storage\win.exe and identified by its known SHA256 hash
This rule detects network communication, DNS queries, email interactions, and URL clicks associated with known TA419 threat actor infrastructure. It monitors multiple telemetry sources to identify indicators of compromise (IOCs) such as specific domains, IP addresses, and email addresses.
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
The following analytic detects the creation of an NTFS alternate data stream (ADS) accessed over a local administrative share targeting the loopback address (127.0.0.1).
It leverages Windows Security Event Logs with EventCode 5145 to identify this activity.
Legitimate local processes access files directly rather than through a local SMB share.
This behavior is a hallmark of the ShieldBreak exploit, which abuses a symbolic link swap through a loopback share to redirect a privileged, Defender-driven write into an alternate data stream on a system-owned file, ultimately landing attacker content in C:\Windows\System32.
If confirmed malicious, this activity indicates an in-progress local privilege escalation attempt and should be investigated immediately.
It leverages Windows Security Event Logs with EventCode 5145 to identify this activity.
Legitimate local processes access files directly rather than through a local SMB share.
This behavior is a hallmark of the ShieldBreak exploit, which abuses a symbolic link swap through a loopback share to redirect a privileged, Defender-driven write into an alternate data stream on a system-owned file, ultimately landing attacker content in C:\Windows\System32.
If confirmed malicious, this activity indicates an in-progress local privilege escalation attempt and should be investigated immediately.
This rule detects a classic port knocking sequence followed by a connection to sensitive services (SSH, Telnet, RDP, VNC, WinRM). The rule identifies devices performing rapid connections to multiple different ports within a short window, which is indicative of a port knocking attempt used to trigger service exposure, followed by an immediate attempt to connect to that exposed service.
Detects the creation of scheduled tasks on remote hosts by monitoring for the NetrJobAdd function call (opnum 0) against the ATSVC RPC interface (UUID: 1FF70682-0A51-30E8-076D-740BE8CEE98B). This interface is associated with the legacy Windows AT scheduler, which is frequently abused by offensive security tools like Impacket's atexec for remote command execution and lateral movement.
Detects the creation of persistence mechanisms through both Registry Run keys and Scheduled Tasks within a one-hour window, specifically targeting names indicative of masquerading as legitimate update or helper components.
Detects the execution of known tunneling binaries (ngrok, cloudflared) or network connections to tunneling service domains (ngrok.io, ngrok-free.app, trycloudflare.com), which are frequently used to establish unauthorized remote access or bypass perimeter security controls.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Page 2 of 1866



