Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects network traffic patterns associated with ARToken-style OAuth device code phishing attacks, specifically monitoring for initial backend requests to Cloudflare Workers infrastructure, response payloads containing known phishing template indicators, and subsequent polling activity against device code endpoints that indicate an active phishing session.
This rule detects email-based phishing campaigns impersonating voicemail notifications ('New VM Received') that utilize Mailchimp click tracking to redirect recipients to landing pages hosted on the .sibpages.com domain, often associated with Brevo/Convrrt services.
Detects automated mailbox monitoring (mailbox access cadence) followed by searches for sensitive finance-related keywords (e.g., invoice, payment, wire, ACH). This pattern is characteristic of a 'Box Monitor' or 'Inbox Monitor' actor, which maintains persistence via API polling to exfiltrate financial information from a compromised account.
This rule detects interactive or user-triggered execution of PowerShell carrying indicators of payload downloading, inline evaluation, or Base64 encoding. Because explorer.exe is the parent process, it typically signifies a payload delivered via email/web that a user opened directly such as an .lnk shortcut.
Detects evidence of account persistence and potential mailbox manipulation following an anomalous sign-in event in Google Workspace. The rule identifies suspicious post-compromise activity such as the addition of new MFA methods, new OAuth application grants, or mailbox forwarding/inbox rules, which are consistent with the reuse of captured authenticated sessions.
Detects a potential brute force or password spraying attempt by identifying instances where a single IP address targets 8 or more distinct user accounts with failed authentication attempts (Event ID 4625) within a 30-minute window.
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
This rule detects multiple suspicious file write operations on a Linux host, specifically targeting directories often used for persistence such as /etc/apt/apt.conf.d, /etc/profile.d, and /etc/cron.d. The rule flags hosts where at least two of these specific persistence techniques are utilized within a 24-hour window, which is indicative of an automated, redundant persistence strategy often employed by cryptocurrency miners like XMRig.
Detects suspicious command line activity or network interactions targeting MongoDB, characterized by the use of 'eval' combined with specific function calls (such as 'process', 'load', 'require', or constructor-chaining) indicative of attempts to escape the MongoDB JavaScript sandbox.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
This rule detects access to known malicious domains used in vishing-themed Adversary-in-the-Middle (AiTM) phishing campaigns. Attackers use these domains to deceive users into providing MFA credentials or session tokens, often following a voice phishing interaction where victims are directed to these sites to register or set passkeys.
This rule detects inbound Microsoft Teams calls originating from external or federated tenants where the caller's display name attempts to mimic internal IT support, help desk, or departmental roles. This behavior is a hallmark of vishing (voice phishing) attacks, often used as a secondary phase in social engineering campaigns following initial contact via email.
This rule detects potentially malicious search activity in Microsoft SharePoint by monitoring for high-frequency queries that include specific site class patterns ('STS_Site' or 'STS_Web') and a document ID range search pattern ('indexdocid'). This behavior is characteristic of an adversary attempting to enumerate or scrape documents within a SharePoint environment.
Detects exploitation attempts by the CARBONATO botnet targeting exposed Docker daemons. The rule monitors for container escape techniques using 'nsenter' to access host namespaces, the execution of specific malicious entrypoint scripts, the use of known malicious container image references, and the creation of privileged containers with host bind mounts, which are indicative of host filesystem and network compromise.
This rule detects known malicious activity including network connections to a specific C2 IP address (69.48.229.140), downloading files from specific C2 URLs, the presence of known malicious file hashes (SHA256), and communications involving specific actor-associated email addresses.
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.



