Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
Detects a sequence of events characteristic of exploitation against RouterOS (CVE-2026-67276/CVE-2026-86060), involving a failed SSH login attempt with the username '-2', followed by the creation of a new user account within the same SSH session, and a successful login with that newly created account.
Detects a sequence of events characteristic of exploitation against RouterOS (CVE-2026-67276/CVE-2026-86060), involving a failed SSH login attempt with the username '-2', followed by the creation of a new user account within the same SSH session, and a successful login with that newly created account.
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
KQL Query
Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
Detects anomalous Telnet (TCP port 23) traffic associated with Mirai-variant botnet propagation, such as scanning for new targets or inbound compromise attempts, often following cPanel/WHM vulnerabilities.
This rule detects unauthorized or anomalous file modifications or creations to machine learning training datasets (e.g., fine-tuning data, training corpora) by users not belonging to the authorized data engineering group, occurring within one hour of a scheduled training or fine-tuning job execution. This behavioral pattern is indicative of potential data poisoning, where an adversary attempts to inject malicious data into the training set to bias or compromise the resulting model.
Detects network connection events associated with the download of machine learning model artifacts from public hubs that display indicators of malicious intent, such as unverified or newly created publisher accounts, missing or invalid cryptographic signatures, or the presence of embedded executable/pickle-deserialization payloads.
Detects network connection events associated with the download of machine learning model artifacts from public hubs that display indicators of malicious intent, such as unverified or newly created publisher accounts, missing or invalid cryptographic signatures, or the presence of embedded executable/pickle-deserialization payloads.
Detects malicious instruction-override payloads, hidden HTML comments, or obscured text (e.g., zero-font size) in third-party content ingested into LLM/RAG systems, commonly used for indirect prompt injection.
Detects anomalous, high-volume querying against machine learning inference endpoints. The rule identifies potential model extraction or data exfiltration attempts by flagging high counts of requests from a single user/API key, particularly during off-hours or with high variance in unique inputs, which may indicate automated efforts to reconstruct proprietary models or extract sensitive training data.
Detects malicious instruction-override payloads, hidden HTML comments, or obscured text (e.g., zero-font size) in third-party content ingested into LLM/RAG systems, commonly used for indirect prompt injection.
Detects anomalous, high-volume querying against machine learning inference endpoints. The rule identifies potential model extraction or data exfiltration attempts by flagging high counts of requests from a single user/API key, particularly during off-hours or with high variance in unique inputs, which may indicate automated efforts to reconstruct proprietary models or extract sensitive training data.


