Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects AvisLoader Windows loader requiring both decoy non-executable packer-named sections and an embedded c-toxcore developer build path to co-occur in a valid PE
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
Detects outbound HTTP requests to identified scam infrastructure (e.g., herokuapp domains) containing platform-specific query parameters (win or mac). This behavior is indicative of a user interacting with a malicious site that is delivering an OS-tailored locker or malware payload.
Detects outbound HTTP requests to identified scam infrastructure (e.g., herokuapp domains) containing platform-specific query parameters (win or mac). This behavior is indicative of a user interacting with a malicious site that is delivering an OS-tailored locker or malware payload.
Detects endpoint network connections to Heroku-hosted domains containing Google Ads tracking parameters (gclid, gad_source, gad_campaignid). This activity is associated with the initial staging phase of 'ShopEase' style malware delivery chains, where users are directed to decoy pages that prepare the environment for subsequent malicious browser-based actions.
Detects outbound HTTP requests to identified scam infrastructure (e.g., herokuapp domains) containing platform-specific query parameters (win or mac). This behavior is indicative of a user interacting with a malicious site that is delivering an OS-tailored locker or malware payload.
Detects endpoint network connections to Heroku-hosted domains containing Google Ads tracking parameters (gclid, gad_source, gad_campaignid). This activity is associated with the initial staging phase of 'ShopEase' style malware delivery chains, where users are directed to decoy pages that prepare the environment for subsequent malicious browser-based actions.
Detects anomalous, rapid execution of a high volume of diverse offensive security tools (scanners, exploitation frameworks, and C2 agents) from a single parent process within a short window, which is characteristic of automated LLM-driven orchestration or scripted attack tool chaining.
Detects outbound HTTPS connections to major generative AI inference endpoints originating from non-browser, non-development tool processes at regular intervals. This activity is indicative of beaconing behavior, where malware (specifically families like LAMEHUG) leverages LLM APIs for dynamic command generation, payload obfuscation, or C2 instruction retrieval, bypassing traditional security controls.
Detects coordinated activity patterns across multiple distinct tenant environments within a one-hour window. The rule looks for shared infrastructure (C2 domains), malicious tool hashes, or specific agentic-CLI command line signatures (e.g., related to orchestration, reconnaissance, or exfiltration) that suggest an AI-orchestrated actor or automated attack campaign affecting multiple organizations simultaneously.
Detects the execution of common remote monitoring and management (RMM) software on a host shortly after the associated user account underwent a password or MFA reset, a pattern indicative of help-desk impersonation (vishing) followed by unauthorized remote access setup.
Detects malformed HEIF/HEIC image files with anomalous ftyp/box structure consistent with the libheif memory corruption exploit (CVE-2026-32882) used against Discourse forum image upload endpoints
This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
This rule detects network connections to domains and IP addresses associated with known malicious TLS CA infrastructure (TLC DV TLS CA) identified by JA4X fingerprints. It monitors endpoint network telemetry for communication with identified command-and-control (C2) servers.
Detects the creation or modification of Registry keys within 'Image File Execution Options' (IFEO) intended to associate a debugger with security-critical or monitoring binaries (e.g., Sysmon, Filebeat). This technique is used for defense evasion and persistence by intercepting or preventing the execution of security tools.
Detects attempts to terminate or delete security-related services and logging agents, such as Sysmon, Filebeat, and various endpoint protection agents, using legitimate Windows system utilities like taskkill, sc, or wmic.
Detects modifications to the creation time of web-accessible script files (.aspx, .php, .asp, .jsp) located in common web directories (wwwroot, inetpub). Adversaries often use timestomping to hide the creation of backdoored web shells, making them appear older and potentially bypassing forensic or integrity-checking mechanisms.
Page 202 of 1871


