Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the presence of known artifacts associated with the GhostContainer backdoor, including indicators of Neo-reGeorg web shell usage, ysoserial payloads, and exploitation attempts targeting the CVE-2020-0688 vulnerability via VIEWSTATE manipulation.
This rule monitors for suspicious activity originating from the WinRM service host (wsmprovhost.exe). It detects when command shells (cmd.exe, powershell.exe) are spawned by WinRM with known malicious command-line arguments (e.g., Evil-WinRM tools), monitors for the creation of potentially malicious configuration files (e.g., config.toml), and identifies established network connections to common WinRM ports (5985/5986) to detect unauthorized remote sessions.
Detects a sequence of events consistent with credential dumping of sensitive Windows registry hives (SAM, SYSTEM, SECURITY). The attack involves querying shadow copies using vssadmin, creating a symbolic link to the shadow copy volume via mklink, and copying the hive files from that location. Cleanup attempts using rmdir are also monitored.
Detects a multi-stage installation of the Level RMM agent. This rule monitors for a correlation of events including the execution of 'LevelInstaller.exe' with specific installation arguments, file drops in potentially spoofed vendor paths (Dell or Level), the creation of a 'Level' service, and the addition of a 'Level Watchdog' scheduled task on the same device within a 24-hour window.
Detects potential lateral movement or pivot attempts by correlating repeated failed RDP logons (RemoteInteractive) against sensitive targets (Domain Controllers, File Servers, Backup Servers) with concurrent security tool blocks (e.g., Microsoft Defender Antivirus, Exploit Guard) on the originating beachhead device within a 4-hour window.
Detects a sequence of suspicious process executions related to the 'RemoteAgent' application, specifically monitoring for MSI-based installations, NSSM service management, and API checks across a device. The rule aggregates distinct process events per device and flags if two or more distinct indicators are identified within a 14-day window.
This rule detects the creation of a scheduled task using an XML definition located in the user's AppData\Local\Temp directory, which is a common staging location for malware. This event is correlated with subsequent high-frequency, short-lived execution of pythonw.exe using .pyw scripts, characteristic of automated implant persistence and re-launch mechanisms.
Detects the creation of a scheduled task using the 'schtasks.exe' utility where the task name is 'MultiUpdater' and the task definition is imported from a file with a specific naming convention and extension (mgk, tmp, or xml) in the root directory.
Detects the execution of PowerShell with command-line arguments that suggest programmatically capturing or redirecting console output using ScriptBlock techniques (Create, Console, In, ReadToEnd). This pattern is often associated with obfuscated script execution, in-memory payloads, or attempts to bypass logging by capturing output via .NET streams.
Detects the execution of rundll32.exe with a command line referencing a DLL file stored in the C:\ProgramData directory. This pattern is commonly used by adversaries to execute malicious code while masquerading as legitimate system activity, particularly when initiated by command shell or browser processes.
Detects network activity characteristic of the CVE-2019-0708 (BlueKeep) Remote Desktop Services exploit, including specific RDP negotiation patterns and subsequent RDP service crashes or resets potentially indicative of a successful or failed exploitation attempt.
Detects a sequence of suspicious activities associated with credential dumping and inhibiting system recovery. The rule tracks when a user account executes multiple commands related to volume shadow copies (vssadmin, rmdir, mklink) or attempts to copy sensitive registry files (SAM, SYSTEM, SECURITY) within a 15-minute window on the same device.
Detects activity associated with a potential RMM (Remote Monitoring and Management) agent communicating with known malicious infrastructure and accessing sensitive files like credentials or IDs. This often indicates an adversary leveraging legitimate RMM tooling for post-compromise activity or exfiltration.
Detects instances where browser processes (Chrome or Edge) are spawned by smartscreen.exe and subsequently access sensitive browser storage files such as Login Data, Cookies, or Local State. This pattern is indicative of a process injection or masquerading chain used to extract credentials or session data.
Detects instances where Python interpreters (python.exe or pythonw.exe) are executed from a subdirectory within ProgramData that matches a 32-hex character pattern, initiated by the 7zip archive utility (7za.exe). This pattern is indicative of a self-extracting archive or malicious installer unpacking and executing Python scripts in a stealthy, non-standard location.
Detects anomalous process execution originating from the PaperCut application server process, specifically targeting the SetupCompleted servlet endpoint. This pattern is indicative of an exploitation attempt, such as CVE-2026-81578, where unauthenticated requests trigger backend server actions before proper access validation.
Detects the execution of common command-line or scripting interpreters (cmd, powershell, cscript, etc.) spawned by the ScreenConnect remote administration client. This is a common pattern used by attackers leveraging legitimate remote access tools for post-exploitation activities and lateral movement.
This rule detects the execution of the Rubeus tool, a known C# toolkit for raw Kerberos interaction. The rule specifically alerts on command-line arguments associated with common Kerberos attacks such as Kerberoasting, requesting TGT/TGS tickets, and performing Pass-the-Ticket operations.
Detects the creation or modification of specific system driver files (nvfsflt64.sys, Alinubx.sys) combined with the installation or initiation of a Windows service associated with NVIDIA filter names. This behavior is often indicative of persistence mechanisms, potential rootkit activity, or the deployment of vulnerable drivers (BYOVD).
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
Page 220 of 1871


