Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
This rule detects network requests directed at raw.githubusercontent.com that attempt to retrieve 'init.dat' or files named with a specific GUID format, patterns which are characteristic of the Kimsuky threat group using GitHub as a dead drop resolver for C2 infrastructure discovery.
Detects the execution of PowerShell with hidden window styles and encoded commands, initiated with High Integrity (Admin) privileges. This pattern is often indicative of bypasses for User Account Control (UAC) or malicious script execution where an adversary attempts to run elevated code while minimizing user visibility.
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects modifications to Group Policy Objects (GPOs) or GPO links in Active Directory, specifically targeting known malicious GPO identifiers, GPO payloads, or changes to policy versioning and linking that indicate unauthorized configuration changes for persistence or privilege escalation.
Detects a cluster of Windows Event IDs 4740 (Account Lockout) or 4724 (Password Reset) targeting the local 'Administrator' account across multiple hosts within a short time window. This activity is indicative of automated or mass account manipulation often associated with ransomware payloads or centralized GPO-based credential tampering.
Detects the presence of PAYLOAD ransomware ELF binaries specifically configured to target VMware ESXi environments. The detection logic looks for a combination of ELF magic bytes, the 'PAYLOAD' string, references to common virtual machine file extensions (e.g., .vmdk, .vmx), and usage of ESXi-specific administration tools such as esxcli or vim-cmd.
Detects a suspicious pattern across the environment where a large number of devices apply Group Policy Objects (GPO) shortly after rebooting. This behavior is indicative of potential unauthorized GPO modification used as a persistence or execution mechanism, where malicious logic is staged within a GPO to trigger across the domain upon machine startup.
Detects a significant number of endpoints processing Group Policy computer configurations within a short time window. This activity is indicative of a synchronized event, such as a domain-wide application of a newly modified or deployed Group Policy Object (GPO), which may follow a 'time-bomb' malicious GPO detonation or unauthorized policy change.
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.


