Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects potential browser-based infostealer activity where a non-standard process, launched from temporary or user-download directories, accesses sensitive browser data files (cookies, login data) followed by a suspicious outbound network connection to a previously unseen domain, matching common patterns for LummaStealer or Vidar malware.
Detects high-risk domain account activity, specifically identifying either impossible-travel authentication patterns in cloud logs or rapid, multi-host interactive authentication fan-out within one hour. These detections are further correlated with subsequent RDP or WinRM session establishment, indicating potential lateral movement or compromise of legitimate accounts.
This rule detects potential process injection or process hollowing attempts by correlating Sysmon Event ID 10 (ProcessAccess) events indicating process memory modification permissions (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) with subsequent Sysmon Event ID 8 (CreateRemoteThread) events targeting the same process. This behavior is indicative of an adversary injecting malicious code into a legitimate host process (e.g., svchost.exe, explorer.exe).
Detects processes querying registry keys or accessing file paths associated with common virtualization and sandbox environments (e.g., VMware, VirtualBox, Hyper-V, Sandboxie). This behavior is often indicative of malware attempting to identify if it is running in an analysis or sandbox environment to evade detection.
Detects attempts to disable, stop, or reconfigure security software (Antivirus, EDR, Endpoint Protection) on Windows endpoints by abusing legitimate administrative utilities such as sc.exe, net.exe, taskkill.exe, wmic.exe, and PowerShell to tamper with service configurations or kill security-related processes.
Detects host-side indicators of potential container escapes and unauthorized access, including mounting sensitive container runtime sockets, executing containers with privileged flags, host namespace sharing, and the use of nsenter to break out of a container context.
Detects high-privilege OAuth consent grants to applications shortly followed by suspicious mailbox modifications, such as creating new inbox or transport rules. This behavior is indicative of a post-compromise activity where an adversary uses an illicitly granted OAuth application to maintain persistence or exfiltrate data from an Exchange Online environment.
Detects high-risk administrative activity on VMware ESXi or vCenter servers that is consistent with pre-ransomware staging, such as disabling lockdown mode, disabling syslog forwarding, mass deletion or modification of virtual machine files (.vmdk/.vmx), or shell command execution related to encryption tool staging.
Detects potential exploitation of Active Directory Certificate Services (AD CS) misconfigurations (specifically ESC1, involving client-auth EKU and enrollee-supplies-subject). The rule correlates certificate issuance events (4886, 4887, 4888) involving sensitive templates or suspicious subject alternative name (SAN) mismatches with subsequent Kerberos PKINIT authentication (4768) events using the issued certificate.
This rule monitors network device audit logs for suspicious activities that indicate potential persistence or defense evasion on edge/VPN/router appliances. It specifically flags configuration changes, creation of new administrative accounts, addition of unauthorized SSH keys, and the disabling of logging/syslog export, which are common tactics for maintainig unauthorized access on network infrastructure.
This rule detects potentially malicious activity involving Service Principals in Microsoft Entra ID. It identifies two scenarios: 1) Impossible travel, where a service principal authenticates from two distinct geographic locations within a 60-minute window, and 2) Administrative modifications to a service principal's credentials or authentication methods (e.g., adding secrets, certificates, or MFA methods), which may indicate persistence or credential abuse.
Detects potential SaaS supply-chain attacks where a third-party application or connector triggers an OAuth permission scope escalation or publishes a new version, followed by the associated service account initiating outbound network connections to rare or newly-registered domains within a 24-hour window.
Detects the reuse of a session or refresh token within a short timeframe (<= 900 seconds) where the source IP location, device identifier, or User-Agent string has materially changed. This behavior is indicative of Adversary-in-the-Middle (AiTM) attacks, where a session cookie has been stolen and replayed from an attacker's infrastructure to hijack a legitimate user's session.
Detects a potential mass-encryption event by identifying a single host rapidly renaming or rewriting a large volume of files across multiple SMB network shares within a short timeframe, where the renamed files consistently adopt a single file extension.
Detects lateral movement via SMB by identifying multiple connections to Windows admin shares (ADMIN$ or C$) followed within a 10-minute window by the creation of a remote service, often indicative of techniques like PsExec. This pattern detects suspicious fan-out behavior where a single source host interacts with multiple targets.
Detects the creation of scheduled tasks via schtasks.exe or native Windows event logs that exhibit suspicious characteristics commonly associated with persistence mechanisms. These characteristics include tasks triggered at logon or system startup, tasks running with elevated SYSTEM privileges, tasks configured to be hidden, or tasks executing binaries from temporary, user-writable directories (Temp, AppData, Public). This pattern is often observed in attack chains leveraging RMM tools or delivery mechanisms like ClickFix.
Detects successful VPN authentication events where no multi-factor authentication (MFA) method is reported in the logs. This behavior may indicate an account compromise where an adversary has bypassed MFA or is using a legacy account that lacks MFA enforcement.
Detects common Windows system binaries (svchost.exe, csrss.exe, lsass.exe, explorer.exe) executing from non-standard directories, which is a common indicator of process masquerading to evade detection.
This rule detects unauthorized or unauthenticated attempts to call the NetrServerPasswordSet2 method on a Domain Controller via the MS-NRPC (Netlogon) interface, which is indicative of an exploitation attempt related to CVE-2020-1472 (Zerologon). This vulnerability allows an attacker to bypass authentication and reset a Domain Controller's computer account password, leading to full domain compromise.
Detects the execution of LNK files masquerading as PDF files through the use of double extensions (e.g., .pdf.lnk). The rule monitors for processes spawned by explorer.exe that contain '.pdf.lnk' in the command line and trigger child processes like PowerShell, CMD, WScript, or MSHTA, which are common indicators of malicious intent.
Detects an exploitation attempt targeting SharePoint through the EditingPageParser by injecting a Register directive. This attempt involves bypassing SafeControls through specifically crafted HTTP POST requests to ToolPane.aspx, utilizing the GetPartPreviewAndPropertiesFromMarkup function to execute malicious tag patterns.
