Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous, chained execution patterns initiated by AI agents integrated with Model Context Protocol (MCP) servers. The rule identifies a multi-stage sequence involving the invocation of browser automation tools followed by shell execution and subsequent outbound network activity, potentially indicating an AI-driven attack chaining filesystem, shell, or cloud-API access in an unauthorized manner.
This rule identifies potential infections associated with the MacSync malware family by matching process, file, and network indicators (hashes, malicious domains, and specific payload URLs) against endpoint telemetry. It monitors for execution of known malicious binaries, file creation events, and communication with identified command-and-control infrastructure.
This rule identifies potential infections associated with the MacSync malware family by matching process, file, and network indicators (hashes, malicious domains, and specific payload URLs) against endpoint telemetry. It monitors for execution of known malicious binaries, file creation events, and communication with identified command-and-control infrastructure.
This rule detects activities associated with the MacSync backdoor, specifically focusing on persistence mechanisms such as LaunchAgent manipulation, .repair-run scripts, and suspicious GIT hook usage. It also correlates these events with the termination of macOS notification agents (BTMNotificationAgent, NotificationCenter, BackgroundTaskManagementAgent), which is a tactic used to suppress security alerts during malicious operations.
Detects post-exploitation activity against Citrix NetScaler appliances associated with CVE-2026-8452. The rule specifically monitors for HTTP GET requests targeting PHP files within the /var/vpn/theme/ directory, accompanied by efforts to execute shell commands (bin/sh) via the web server.
Detects AI agent tooling (e.g., LangChain, Copilot, Claude Code) performing read operations on databases containing sensitive data patterns, or performing suspicious bulk data enumeration. The rule monitors Azure SQL Database security audit events for suspicious application name signatures and non-schema introspective queries.
Detects phishing messages that deliberately mix writing systems/scripts or use homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. This is the only translation that implements true sender-novelty checking via baseline lookups (a sending domain must be new to both the specific recipient and the organization as a whole to add risk). A weighted score (script-mixing=2, homoglyph=3, phishing vocabulary=2, sender-novelty=1, threshold=6) requires multiple corroborating signals before firing. Note: unlike the SPL/S1QL/CQL/CortexQL translations, this version does not strip brand/product tokens before the script check.
Detects phishing messages that deliberately mix writing systems/scripts or use homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. This is the only translation that implements true sender-novelty checking via baseline lookups (a sending domain must be new to both the specific recipient and the organization as a whole to add risk). A weighted score (script-mixing=2, homoglyph=3, phishing vocabulary=2, sender-novelty=1, threshold=6) requires multiple corroborating signals before firing. Note: unlike the SPL/S1QL/CQL/CortexQL translations, this version does not strip brand/product tokens before the script check.
Detects phishing messages that deliberately mix writing systems/scripts or use homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. This is the only translation that implements true sender-novelty checking via baseline lookups (a sending domain must be new to both the specific recipient and the organization as a whole to add risk). A weighted score (script-mixing=2, homoglyph=3, phishing vocabulary=2, sender-novelty=1, threshold=6) requires multiple corroborating signals before firing. Note: unlike the SPL/S1QL/CQL/CortexQL translations, this version does not strip brand/product tokens before the script check.
KQL Query
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that mix writing systems/scripts/homoglyphs in the Subject line as one corroborating signal within a broader, multi-signal phishing pattern.
Detects phishing messages that mix writing systems/scripts/homoglyphs in the Subject line as one corroborating signal within a broader, multi-signal phishing pattern.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.


