Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Monitors network connections initiated by the Logitech Options Plus agent process (logioptionsplus_agent.exe) on a specified host. This rule facilitates tracking of outbound communications generated by this background service.
Detects evidence of a SharePoint pre-authentication RCE exploit chain where an adversary injects a malicious Namespace containing an ExpandedWrapper-wrapped XamlServices payload (e.g., ObjectDataProvider or LosFormatter gadget) into the w3wp.exe worker process. This specifically looks for command-line arguments indicative of deserialization-based exploit attempts targeting SharePoint web server components.
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
Detects PowerShell processes using the .NET System.IO.File methods (SetLastWriteTime, SetCreationTime, SetLastAccessTime) to modify file timestamps, a common anti-forensic technique to obfuscate file creation or modification times.
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
Detects the use of csc.exe (C# compiler) launched from PowerShell with hidden or bypass flags, as well as the subsequent execution of cvtres.exe. This activity is commonly associated with fileless malware techniques where helper classes or payloads are compiled and executed in-memory at runtime to evade detection.
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
Detects the creation of a scheduled task via schtasks.exe initiated by wscript.exe or cscript.exe where the task configuration or execution occurs within common user-writable directories (e.g., AppData, Temp, Downloads). The rule specifically flags behavior involving multiple task invocations in a short time frame, which is indicative of persistence mechanisms used by scripts.
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
This rule identifies developer or contractor workstations that have Node.js/npm installed but currently lack active EDR sensor coverage (i.e., the sensor is either not onboarded or not in an active state). It employs a 24-hour grace period to filter out transient onboarding issues and ensures that the device has reported activity within the last 7 days to avoid alerting on decommissioned hardware. This gap in visibility increases the risk of undetected supply-chain malware execution and credential theft on sensitive developer endpoints.
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
Page 205 of 1871


