Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
Detects the execution of PowerShell via a shortcut (.lnk) file that attempts to download and execute remote content using 'Invoke-WebRequest'. The command lines use common obfuscation techniques like 'Hidden' window style and 'Bypass' execution policy, targeting specific known malicious URL patterns or filename keywords.
Detects the execution of cloud CLI tools (aws, az, gcloud) using Unix shells (bash, sh) to perform sensitive operations such as listing secrets, keys, or metadata, which may indicate credential discovery or exfiltration.
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
Detects activity from known Storm-3168 (JADEPUFFER) campaign IP addresses across Azure control-plane, sign-in, and App Service logs. The rule monitors for malicious indicators in Azure Activity logs, Azure Sign-in logs, and Service Principal sign-ins, as well as specific sensitive URI paths (e.g., shells, admin login paths) within App Service HTTP logs.
Detects a suspicious sequence of behavior where an Azure service principal authenticates and immediately performs broad reconnaissance (enumeration) across multiple subscriptions and resource types. This pattern is often indicative of an adversary using a compromised service principal credential to map out an environment.
Detects a service principal attempting to delete multiple Azure SQL databases in a short timeframe, resulting in failures. This pattern is characteristic of malicious data destruction activity, such as that observed in Storm-3168 (JADEPUFFER) campaigns, but accounts for the possibility of misconfigured infrastructure-as-code pipelines by requiring a high volume of failed requests across distinct resources.
This rule detects reconnaissance activity targeting Azure App Service instances, specifically looking for attempts to access web-shell-like files, WordPress administration paths, PHP-CGI endpoints, or LangFlow code validation paths. It identifies potential Storm-3168 actor infrastructure through known IOCs or through patterns of high-volume, path-diverse HTTP requests that deviate from typical noise, helping to distinguish targeted probing from common internet background scanning.
This rule detects reconnaissance activity targeting Azure App Service instances, specifically looking for attempts to access web-shell-like files, WordPress administration paths, PHP-CGI endpoints, or LangFlow code validation paths. It identifies potential Storm-3168 actor infrastructure through known IOCs or through patterns of high-volume, path-diverse HTTP requests that deviate from typical noise, helping to distinguish targeted probing from common internet background scanning.
Detects a precursor pattern identified as JADEPUFFER, where a failed 'ListKeys' operation (indicating an attempt to discover or access keys for a non-existent storage account) is immediately followed by a burst of destructive delete operations on critical cloud resources (e.g., storage, databases, key vaults) by the same actor.
Detects a suspicious pattern often associated with Storm-3168 (JADEPUFFER) activity: prolonged, high-volume Azure resource enumeration by one service principal, followed shortly by a second service principal performing rapid, multi-subscription enumeration from the same source IP address.

