Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects high-frequency, automated interactions with popular AI assistant web interfaces (e.g., Gemini, Perplexity, Claude, Copilot) from common browser processes. This pattern often indicates unauthorized automated data submission or scraping, which may follow or facilitate automated exfiltration of browser-resident data.
This rule detects potential exploitation attempts targeting VLC media player, specifically focusing on the CVE-2026-56711 integer overflow vulnerability. The rule identifies instances where VLC processes a PNG file originating from untrusted locations (such as Downloads, Temp, or removable media) shortly after that file was created or modified on the host.
In DeviceNetworkEvents, we can find both JA4 and JA4S inside AdditionalFields for some TLS connections. This is interesting because we can look at both sides of the same TLS communication. We can compare clients, servers and JA4/JA4S combinations, and look for patterns or connections that behave differently from what we normally see. The following KQL extracts and decodes both fingerprints from the same network event.
This rule detects potentially malicious child processes spawned by processes associated with Microsoft Semantic Kernel agents. These agents may be exploited to execute administrative tools, living-off-the-land binaries (LOLBins), or networking utilities commonly used in post-exploitation activities, such as credential dumping, discovery, or command execution.
Detects the initiation of the OAuth 2.0 Device Authorization Grant flow via command-line arguments within standard web browsers. This flow is frequently exploited in phishing campaigns to obtain unauthorized access tokens by tricking users into entering a device code on a malicious or attacker-controlled authorization page.
Detects the presence of prompt-injection framing and malicious intent instructions within the first few lines of source code files. These strings are designed to deceive LLM-based SAST or code review tools into ignoring, misclassifying, or bypassing security analysis of malicious code.
Detects the creation of a shortcut (.lnk) file by the process 'OrionQuests-Setup.exe'. This activity is often associated with installers or applications placing shortcuts on the desktop or in startup folders for persistence or execution initiation.
Detects Kerberos TGS (Ticket Granting Service) requests where the ticket encryption type is RC4 (0x17). This behavior, commonly referred to as Kerberoasting, involves requesting service tickets for accounts with service principal names (SPNs) set, often to perform offline brute-force attacks against the service account's password hash. The rule excludes common service account patterns and machine accounts to reduce noise.
Detects outbound HTTP/HTTPS POST requests where the URI, query string, or path contains evidence of sensitive credential material, such as AWS access keys, private key blocks, or common environment variable patterns, indicative of potential credential harvesting and exfiltration to an external destination.
Detects suspicious PE files that masquerade as Mozilla Firefox by using Firefox-related product names and metadata, but lack valid Mozilla Corporation code-signing signatures and are located within the ProgramData directory.
Detects the creation of a scheduled task containing the string 'Google Chrome Update' in the command line, where the task is not the legitimate 'GoogleUpdateTaskMachine' task. The rule specifically targets tasks that execute PowerShell or arbitrary executables, which is a common persistence technique used by adversaries to mask malicious tasks as legitimate software updates.
Detects the execution of PowerShell from a shortcut (.lnk) file, particularly when suspicious command-line arguments such as hidden windows, encoded commands, or bypass flags are utilized. This pattern is commonly associated with initial access via malicious attachments or shortcut files.
Detects suspicious PE files that masquerade as Mozilla Firefox by using Firefox-related product names and metadata, but lack valid Mozilla Corporation code-signing signatures and are located within the ProgramData directory.
Detects Python processes (python.exe, python3.exe, pythonw.exe) performing DNS resolution for Microsoft identity, device login, or Graph API endpoints. This activity is consistent with automated tooling, such as python-requests, performing device-code flow polling or API token authentication within an environment.
This rule detects modifications to the Windows hosts file by unauthorized processes. The hosts file is often targeted by adversaries to redirect network traffic, intercept communications, or prevent access to security-related websites.
Detects unauthorized write, create, or rename operations on the Windows HOSTS file (\drivers\etc\hosts). The rule excludes common system processes and paths associated with legitimate administrative or update activities, targeting potentially malicious attempts to redirect network traffic by modifying DNS resolution locally.
Detects instances where PowerShell.exe acts as a parent process or initiator for potentially suspicious process injections into common host processes including csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with code execution or persistence mechanisms where PowerShell injects malicious logic into other processes.
Detects the use of the wevtutil.exe utility to clear the Microsoft-Windows-Defender/Operational event log, a technique used by adversaries to disrupt security monitoring and hide malicious activity.
Detects the execution of the MeshCentral remote management agent (meshagent.exe) or processes masquerading as the agent using the known alias 'mvtcs.exe'. This rule identifies the start of these processes to detect unauthorized or potentially malicious remote management activity.
Detects the execution of PowerShell with suspicious command-line arguments and obfuscation techniques commonly used by attackers to execute malicious code, including base64 encoded commands, bypass of execution policies, dynamic assembly loading, and caret-based obfuscation.
Detects anomalous remote access or VPN login activity for a user account, characterized by either logins from multiple distinct countries or logins occurring during off-hours (between 8:01 PM and 5:59 AM). This rule helps identify potential credential abuse where valid accounts are being leveraged from unexpected locations or times.
Page 218 of 1871



