Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects outbound network connections from internal devices to a set of known malicious IP addresses (217.156.122.129, 37.221.66.43) across commonly abused command-and-control ports (8080, 3480, 9998, 9999, 4444).
Detects outbound network connections from internal devices to a set of known malicious IP addresses (217.156.122.129, 37.221.66.43) across commonly abused command-and-control ports (8080, 3480, 9998, 9999, 4444).
Detects OtterCookie JavaScript-based RAT/infostealer malware artifacts associated with WaterPlum/Contagious Interview campaign
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
Detects periodic outbound network connections (beaconing) to rare remote destinations initiated by processes running from non-standard or user-writable locations. The rule calculates the interval coefficient of variation (CV) between successful connections to identify regular, consistent patterns indicative of command and control communication while excluding known legitimate update and service traffic.
Detects DragonForce ransomware attempting to identify accessible SMB network shares by executing 'net view' commands. This activity is a precursor to encrypting files on reachable administrative shares (e.g., C$) while excluding system-specific shares like ADMIN$.
Detects file operations (open, read, write, rename) involving common sensitive credential files (e.g., .kdbx password databases, .ovpn and .pcf configuration files, .pem, and .ssh directory contents) by processes not authorized to interact with these files.
Detects modifications to registry keys associated with the 'ms-settings' COM object, specifically targeting the shell open command or DelegateExecute value. This technique, commonly referred to as 'ms-settings' hijacking, is used by adversaries to achieve persistence or elevated execution by redirecting legitimate COM object references to malicious payloads.
Detects modifications to registry keys associated with the 'ms-settings' COM object, specifically targeting the shell open command or DelegateExecute value. This technique, commonly referred to as 'ms-settings' hijacking, is used by adversaries to achieve persistence or elevated execution by redirecting legitimate COM object references to malicious payloads.
This rule identifies potential network scanning or propagation activity by detecting a single host initiating SMB (TCP 445) connections to a high number (more than 20) of unique destination IP addresses within a given timeframe. This behavior is often indicative of internal reconnaissance, lateral movement, or worm-like propagation.
This rule detects the execution of processes that contain the command line argument 'Found sid:', which is commonly associated with security identifier (SID) enumeration or lookup tools/scripts, such as those used by security researchers or attackers during reconnaissance.
This rule detects potentially malicious PowerShell activity executed from Windows Explorer with obfuscated arguments (-enc, -w hidden) in conjunction with access to the Windows RunMRU registry key, which tracks commands executed via the Windows Run dialog.
Detects instances where browser extensions, potentially AI-assisted (e.g., Claude, Gemini), trigger automated mail actions (send, forward, summarize) to non-standard, external domains. This behavior may indicate an unauthorized agent attempting to exfiltrate or manipulate email content.
Detects execution of PowerShell with a hidden window and base64-encoded command arguments that targets the file 'WindowsUpdate.log'. This pattern is associated with the CRPx0 (ClickFix) ransomware, where it attempts to drop or interact with a stager file disguised as a legitimate Windows update log file.
This rule detects instances where PowerShell is used to download or execute remote monitoring and management (RMM) tools or remote access software binaries (e.g., AnyDesk, TeamViewer, Atera). This pattern is often indicative of an adversary attempting to establish persistent remote access to a compromised system after initial intrusion.
Detects malicious manipulation of browser-based AI agents where process command-line arguments indicate an attempt to instruct the agent to access, summarize, and exfiltrate email messages from a user's webmail account.
This rule monitors for interactions with known malicious files (by SHA256 hash), connections to confirmed C2 infrastructure (specific IP address and domains), or requests to known malicious URLs. It aggregates indicators across file, process, network, and web browsing telemetry to identify potential threats or compromised systems communicating with known attacker infrastructure.
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
This rule detects potential malicious activity by monitoring for known indicators of compromise, including specific SHA256 file hashes, a known malicious IP address, and URLs associated with identified threats. The detection spans file creation/execution, network connections, and URL visits to block or alert on interactions with suspicious infrastructure.
This rule detects potential malicious activity by monitoring for known indicators of compromise, including specific SHA256 file hashes, a known malicious IP address, and URLs associated with identified threats. The detection spans file creation/execution, network connections, and URL visits to block or alert on interactions with suspicious infrastructure.
Page 207 of 1871


