Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects outbound network connections from internal devices to a set of known malicious IP addresses (45.151.45.31 and 46.166.79.31) which may indicate command and control communication or other malicious activity.
This rule monitors for file and process creation events associated with known FeralWolf threat actor malware, including MQTTDoor, MatrixDoor, RDPSocksProxy, GenieLocker ransomware, fscan, and tools leveraging CVE-2026-31431.
Detects the execution of processes with 'revsocks' in the file name. Revsocks is a known proxy tool often utilized by threat actors for establishing reverse SOCKS proxies, facilitating command and control communication, and bypassing network segmentation.
Detects the execution of PowerShell commands that reference the 'nyx' script from 'raw.githubusercontent.com', combined with common download and execution patterns such as 'Invoke-Expression' or 'Invoke-WebRequest'. This activity is consistent with retrieving and executing remote post-exploitation scripts.
Detects evidence of potential credential dumping from the Local Security Authority Subsystem Service (LSASS) process. The rule monitors for two distinct behaviors: the use of MemProcFS with device memory access flags targeting a RAW file, and the creation of files containing 'lsass.exe', 'minidump', and 'readme.txt' in their paths or filenames, which is characteristic of certain post-exploitation toolkits that harvest LSASS memory.
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
Detects the execution of pythonw.exe spawned by ComputerDefaults.exe, which is a known technique for bypassing User Account Control (UAC) to achieve elevated privileges. This rule specifically tracks instances where a Python script is initiated and subsequently triggered by the UAC-bypassing binary within a 5-minute window.
Detects the creation of a scheduled task using the 'schtasks.exe' utility where the task name is 'MultiUpdater' and the task definition is imported from a file with a specific naming convention and extension (mgk, tmp, or xml) in the root directory.
Detects the execution of rundll32.exe with a command line referencing a DLL file stored in the C:\ProgramData directory. This pattern is commonly used by adversaries to execute malicious code while masquerading as legitimate system activity, particularly when initiated by command shell or browser processes.
Detects a sequence of suspicious activities associated with credential dumping and inhibiting system recovery. The rule tracks when a user account executes multiple commands related to volume shadow copies (vssadmin, rmdir, mklink) or attempts to copy sensitive registry files (SAM, SYSTEM, SECURITY) within a 15-minute window on the same device.
Detects a sequence of suspicious process executions related to the 'RemoteAgent' application, specifically monitoring for MSI-based installations, NSSM service management, and API checks across a device. The rule aggregates distinct process events per device and flags if two or more distinct indicators are identified within a 14-day window.
Detects unexpected child process execution spawned by the ScreenConnect ClientService. This activity is indicative of the exploitation of CVE-2026-84869, which allows for unauthorized file transfer and arbitrary code execution within the context of the remote support agent without requiring user interaction or confirmation.
Detects activity associated with a potential RMM (Remote Monitoring and Management) agent communicating with known malicious infrastructure and accessing sensitive files like credentials or IDs. This often indicates an adversary leveraging legitimate RMM tooling for post-compromise activity or exfiltration.
Detects post-exploitation shell activity spawned from the IIS worker process (w3wp.exe), narrowed to command lines carrying encoded/obfuscated PowerShell flags, remote-download cradles, or basic recon/persistence commands (whoami, certutil, bitsadmin, schtasks, reg add). This reduces noise from benign w3wp.exe-initiated automation while retaining the behavioral pattern seen in the Telerik UI for ASP.NET AJAX unauthenticated RCE chain (webshell/in-memory DLL execution dropping to a shell).
This rule detects the creation of a scheduled task using an XML definition located in the user's AppData\Local\Temp directory, which is a common staging location for malware. This event is correlated with subsequent high-frequency, short-lived execution of pythonw.exe using .pyw scripts, characteristic of automated implant persistence and re-launch mechanisms.
Detects a sequence of events consistent with credential dumping of sensitive Windows registry hives (SAM, SYSTEM, SECURITY). The attack involves querying shadow copies using vssadmin, creating a symbolic link to the shadow copy volume via mklink, and copying the hive files from that location. Cleanup attempts using rmdir are also monitored.
Detects unauthenticated attempts to exploit CVE-2025-3248 in the Langflow 'validate/code' endpoint, characterized by missing authentication headers and the presence of suspicious Base64-encoded payloads or command execution keywords. Additionally, it identifies potential post-exploitation activity where Langflow processes spawn Python subprocesses.
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
This rule detects the execution of npm or node.js commands involving specific, potentially malicious package names or internal project naming patterns often associated with dependency confusion or supply chain attacks. It monitors npm/node CLI arguments for targeted library names or installation commands that deviate from standard organizational behavior.
Page 222 of 1871


