Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects HTML files that employ FlipBook branding as a lure for password-gated smuggling. The detection identifies client-side JavaScript logic that uses PBKDF2 and AES-GCM to decrypt a hidden redirect URL after user interaction with a password prompt.
Detects instances where the Redis server process or the Redis AOF check utility writes directly to common SSH authorized_keys file paths. This behavior is indicative of an attacker exploiting a Redis misconfiguration or vulnerability (e.g., Redis RCE) to establish persistence by injecting an unauthorized SSH key.
This rule detects potential exploitation of CVE-2026-86134, a NULL pointer dereference vulnerability in WatchGuard Fireware. It identifies a burst of authentication-related requests (login, authd, management) targeting a device, followed by system logs indicating a service crash, daemon restart, or core dump within a short correlation window. This behavior is indicative of a Denial of Service attack.
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
Detects anomalous post-authentication reconnaissance activities against the Microsoft Graph API, specifically the enumeration of directory objects, roles, or service principals. The rule triggers when a user account performs multi-endpoint enumeration via the Graph API within 30 minutes of a successful authentication session initiated via a device code flow that was flagged with elevated risk signals. This behavior is consistent with post-compromise reconnaissance techniques such as 'EvilTokens', where an adversary attempts to map the environment after gaining access.
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
This rule detects suspicious activity involving macOS LaunchAgents and files within the 'Application Support/System' directory, often associated with persistence or malicious background execution. The detection looks for the creation or modification of specific plist files (e.g., com.apple.finder.agent.plist) or git-related files in Application Support, correlated with process execution of commands like 'sysnotif-repair', 'launchctl' manipulating agents, or git operations involving custom hooks paths.
This rule detects HTTP POST requests characteristic of the curlRAT malware used by DPRK-affiliated threat actors. The detection looks for a specific POST body format containing 'name=', '&value=', and '&type=' parameters, which indicates C2 communication patterns commonly associated with this specific backdoor.
Detects anomalous HTTP traffic directed to githubusercontent.com containing a custom, non-standard request header 'aohvcoehfg'. This pattern is associated with Kimsuky threat actor activity, specifically related to the 'GitPower' operation involving C2 communication via GitHub repositories.
The following analytic detects when all virtual machines on an ESXi host are abruptly terminated, which may indicate malicious activity such as a deliberate denial-of-service, ransomware staging, or an attempt to destroy critical workloads.


