Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects the execution of the Rubeus tool, a known C# toolkit for raw Kerberos interaction. The rule specifically alerts on command-line arguments associated with common Kerberos attacks such as Kerberoasting, requesting TGT/TGS tickets, and performing Pass-the-Ticket operations.
Detects the creation or modification of specific system driver files (nvfsflt64.sys, Alinubx.sys) combined with the installation or initiation of a Windows service associated with NVIDIA filter names. This behavior is often indicative of persistence mechanisms, potential rootkit activity, or the deployment of vulnerable drivers (BYOVD).
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
Detects instances where explorer.exe initiates cmd.exe with suspicious command-line patterns often associated with malicious script execution or evasion. These include caret-based obfuscation, mixed-case PowerShell invocations, or base64-like blobs, alongside indicators of common malicious file paths or execution policy bypass flags.
This rule detects instances where a process associated with a known StealC command-and-control (C2) IP address subsequently spawns a hidden cmd.exe instance. It correlates network connections to known malicious infrastructure with the creation of hidden command shells within the same device session, specifically looking for common parent processes like web browsers or system utilities.
This rule detects instances where a process associated with a known StealC command-and-control (C2) IP address subsequently spawns a hidden cmd.exe instance. It correlates network connections to known malicious infrastructure with the creation of hidden command shells within the same device session, specifically looking for common parent processes like web browsers or system utilities.
This rule monitors for potential MeshAgent activity associated with the Settra threat actor. It identifies processes that are likely renamed instances of MeshAgent (via metadata inspection), processes attempting to communicate with known C2 IP addresses, and direct network connections to these C2 IP addresses.
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
This rule detects the presence, installation, or execution attempts of the known vulnerable GIGABYTE driver (gdrv.sys). Monitoring for this specific driver is a common practice to identify attempts to perform 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, which can be used for kernel-mode code execution and privilege escalation.
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
This rule detects potential ransomware activity by correlating three distinct events: the execution of a suspicious, potentially obfuscated binary (matching a specific naming pattern of _win64.exe) from an untrusted location (e.g., Temp, AppData, Downloads), followed by a high volume of file modifications or renames with specific ransomware-related extensions (.locked), and the dropping of a known ransom note file (RESTORE_FILES.txt) within a short 15-minute time window.
Detects a network activity pattern from a single host characterized by a high volume of connections to a wide range of remote hosts and ports, combined with an exceptionally low coefficient of variation in inter-request timing. This pattern is indicative of an automated, scriptable agent or AI-driven reconnaissance tool rather than a human-operated scanner, likely performing automated asset discovery or network enumeration.
Detects the installation or execution of virtual camera or synthetic media software followed shortly by the launch of common video conferencing applications on the same endpoint. This behavior may indicate an attempt to inject synthetic video feeds into meetings for impersonation or business email compromise (BEC) attacks.
Detects the execution of high-privilege administrative, firewall, or file-system commands by processes identified as autonomous agent runtimes (e.g., LangChain, AutoGPT) or Robotic Process Automation (RPA) tools. This rule surfaces potential unauthorized infrastructure changes or automated abuse by agents when direct change management validation is absent.
Detects a single source IP address rapidly attempting connections to multiple distinct devices and ports within a short time window. This behavior is indicative of an automated agent or scanner performing reconnaissance and potentially attempting to chain exploitation across multiple targets.
Detects potential exploitation of AI agent frameworks, such as Semantic Kernel, where plugin or tool invocation primitives are abused to execute arbitrary commands or manipulate files via path traversal. The rule monitors for AI-hosting processes (e.g., python.exe, node.exe) spawning shell child processes or file-related commands containing path traversal sequences (e.g., '..\..\') paired with file operation keywords.
Page 221 of 1871


