Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of PowerShell with suspicious command-line arguments and obfuscation techniques commonly used by attackers to execute malicious code, including base64 encoded commands, bypass of execution policies, dynamic assembly loading, and caret-based obfuscation.
Detects anomalous remote access or VPN login activity for a user account, characterized by either logins from multiple distinct countries or logins occurring during off-hours (between 8:01 PM and 5:59 AM). This rule helps identify potential credential abuse where valid accounts are being leveraged from unexpected locations or times.
Detects the execution of the Windows Recovery Environment Configuration Tool (REAgentC.exe) with the '/disable' argument. Adversaries may use this command to inhibit system recovery, preventing users from using built-in Windows recovery options during or after a malicious event.
Detects attempts to clear Windows event logs using built-in utilities such as wevtutil.exe or PowerShell cmdlets (Clear-EventLog, Clear-WinEvent). Adversaries often perform this action to remove traces of malicious activity from the system.
Detects the use of the native Windows reg.exe utility to save the Security Account Manager (SAM) registry hive to a file. This technique is commonly used by adversaries to perform offline credential extraction or to dump local account password hashes.
Detects Microsoft Office applications (Word, Excel, PowerPoint) spawning common LOLBAS (Living Off the Land Binaries and Scripts) child processes. This behavior is a common indicator of macro-based malware or malicious document exploitation where Office applications are used to execute shell commands or scripts for payload delivery or execution.
Detects the execution of 'git checkout' commands involving 'FETCH_HEAD', initiated by Gemini or Node.js runtime environments. This pattern may indicate automated repository synchronization, potential software supply chain activity, or anomalous usage of developer tools.
Detects processes requesting specific access rights to the Local Security Authority Subsystem Service (LSASS) process, which are commonly associated with credential dumping techniques. The rule filters out known security software that performs legitimate LSASS inspection.
Detects instances where AI-assisted coding tools (such as Claude, Copilot, or Gemini) initiate Git operations (clone, checkout, fetch) in a non-interactive context. This behavior may indicate an automated process using AI tools to perform code repository interactions that should typically be user-initiated or are otherwise suspicious in a non-interactive environment.
Detects the creation or start of the PSEXESVC service, which is a characteristic behavior of the PsExec tool used for remote execution and lateral movement.
This rule monitors for potential Kerberos Golden Ticket attacks by detecting specific indicators within Windows security events. It identifies Event ID 4769 with a PAC validation failure status (0x1F), and the use of weak RC4 encryption (0x17) in either TGT requests (Event ID 4768) or service ticket requests (Event ID 4769). These behaviors are often associated with forged Kerberos tickets where the attacker may be using weak encryption or malformed PAC data.
Detects the execution of the Windows cipher.exe utility with the '/w' flag from the command prompt. The '/w' flag is used to overwrite free space on a disk, which is a technique often used by adversaries to perform data destruction or hinder forensic recovery of deleted files.
Detects Kerberos TGS (Service Ticket) requests utilizing the insecure RC4 encryption type (0x17). This pattern is a hallmark of Kerberoasting, where an attacker requests service tickets for SPNs in an attempt to crack the service account credentials offline.
Detects Git command line executions involving 'branch', 'checkout', or 'push' operations that reference what appear to be full commit hashes as branch references. The rule flags instances where 'refname is ambiguous' warnings are generated, which may indicate an attempt to manipulate or interact with git repositories in ways that conflict with existing branches, potentially suggesting malicious repository tampering or discovery activity.
Detects high-frequency failed RDP authentication attempts (Windows Event ID 4625 with LogonType 10) originating from the same source. This pattern is indicative of brute-force or credential guessing attacks against Remote Desktop Services.
This rule detects the creation of .lnk files within the Windows Startup directory. Attackers frequently use this persistence technique to ensure that a malicious script or executable runs automatically upon user login.
Detects the execution of MeshAgent or mvtcs (MeshCentral) binaries, which are commonly used for legitimate remote management but can also be used as unauthorized remote access tools by adversaries.
Detects execution of PowerShell or Command Prompt where the command line contains obfuscated indicators or specific suspicious files and IP addresses, while simultaneously bypassing the execution policy. This is characteristic of malicious script execution or payload delivery attempts.
Detects execution of PowerShell or CMD commands originating from Windows Explorer (explorer.exe) that exhibit characteristics of malicious command-line obfuscation, such as encoded commands, bypass flags, or caret-based character obfuscation.
This rule detects the creation of specific shortcut files (.lnk) within the Windows Startup folder and monitors for the usage of WScript.Shell to interact with the Startup directory. This behavior is commonly associated with persistence mechanisms where an adversary attempts to automatically execute malicious code upon user login.
Detects the installation or service creation of 'gdrv.sys', a known vulnerable GIGABYTE driver often abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to escalate privileges.
Page 219 of 1871

