Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
Detects instances where the ScreenConnect ClientService process initiates a child process that is not a recognized ScreenConnect binary. It further filters for child processes created shortly after a file has been created or modified by the ScreenConnect service, which is often indicative of an adversary using the remote access tool to drop and execute malicious payloads.
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
Page 200 of 1871

