Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the use of 'vim-cmd' or 'esxcli' to power off or terminate virtual machine processes on an ESXi host, which may indicate malicious activity such as ransom-related VM shutdown or service disruption.
Detects the creation of new administrator or technician accounts within the SimpleHelp Remote Monitoring and Management (RMM) platform via API calls. This activity is often associated with unauthorized persistence creation by an adversary who has gained access to the platform.
Detects a process obtaining handle access to the LSASS process (Sysmon Event ID 10) followed by the creation of a file (Sysmon Event ID 11) using an extension other than '.dmp'. This behavior is characteristic of adversaries attempting to obfuscate credential dumping activities by bypassing simple extension-based detection rules.
Detects web application server processes (such as IIS, Apache, Tomcat, Java, Nginx, or Node.js) spawning command-line interpreters or system utilities. This behavior is frequently associated with webshell execution or post-exploitation activities following the exploitation of a public-facing application, often seen in VPN or enterprise software compromises.
Detects the creation of files commonly associated with ransomware notes (e.g., README.txt, HOW_TO_DECRYPT.txt) across multiple directories, which is a strong indicator of the impact phase where files have been encrypted and the adversary is providing recovery instructions.
Detects anomalous authentication behavior originating from a single source IP targeting an SSL VPN gateway. The rule identifies a high volume of unique usernames failing authentication within a short time window, a pattern indicative of password spraying and often associated with initial access attempts on environments lacking multi-factor authentication (MFA), such as those leveraged in Akira ransomware operations.
Detects the use of the bcdedit.exe utility to configure the Windows boot configuration to enter Safe Mode (minimal or with networking), immediately followed by the execution of a shutdown command with the reboot flag. This sequence is a known technique utilized by Akira ransomware affiliates to force a system reboot into a restricted environment where security agents and endpoint detection and response (EDR) tools may fail to load, allowing for undetected encryption.
Detects a burst of lateral movement activity characterized by the use of administrative tools like PsExec or NetExec/CrackMapExec to execute commands or services on multiple distinct target hosts from a single source host within a short window. This pattern is commonly associated with ransomware affiliates or threat actors performing reconnaissance and mass deployment of malicious payloads prior to encryption.
Detects remote command execution patterns associated with the Impacket suite (e.g., wmiexec.py, atexec.py, smbexec.py). The detection identifies cmd.exe processes spawned by WmiPrvSE.exe or svchost.exe that contain specific command-line arguments indicative of Impacket's remote execution behavior, such as output redirection to hidden administrative shares or temporary files.
Detects the execution of rclone.exe or renamed binaries with command-line flags indicative of data exfiltration to cloud storage providers such as S3, Mega, OneDrive, or Google Drive. This behavior is frequently associated with ransomware actors, including Akira, Qilin, and Storm-2570, who use Rclone to perform mass exfiltration of sensitive file share data prior to encryption (double extortion).
Detects attempts to clear Windows event logs using built-in utilities like wevtutil.exe, PowerShell commands (Clear-EventLog, Remove-EventLog), or the detection of Event ID 1102 (Log cleared). This activity is commonly used by adversaries, including ransomware affiliates, to obfuscate their tracks during or after an attack.
Detects unauthorized attempts to dump credentials from the Local Security Authority Subsystem Service (LSASS) process. This includes the execution of known credential-harvesting tools (e.g., Mimikatz, LaZagne, pypykatz), the use of system utilities like procdump and comsvcs.dll to dump process memory, and anomalous direct handle access to lsass.exe by non-system processes. This activity is associated with Storm-2570 post-compromise tradecraft.
Detects Active Directory Directory Replication Service (DRSUAPI) GetNCChanges requests originating from a principal or host that is not recognized as a Domain Controller. This behavior is indicative of unauthorized DCSync operations used to dump NTDS.dit hashes, a common technique for credential harvesting associated with ransomware actors like Qilin.
Detects the execution of reconnaissance commands designed to enumerate Active Directory domain trust relationships. Attackers, including those associated with ransomware operations like INC Ransom, use these tools to map organizational structures and identify pathways for lateral movement and cross-domain propagation.
Detects the execution of reconnaissance commands designed to enumerate Active Directory domain trust relationships. Attackers, including those associated with ransomware operations like INC Ransom, use these tools to map organizational structures and identify pathways for lateral movement and cross-domain propagation.
Detects the creation of scheduled tasks using schtasks.exe that exhibit behaviors associated with common remote execution tools (e.g., Impacket's atexec.py) or staging from insecure directories like Temp, ProgramData, or network shares. These patterns are frequently used by threat actors, including INC Ransom, for lateral movement and remote execution of malicious payloads.
Detects a multi-stage extortion tactic where a host is targeted by a mass creation of initial decryption-style ransom notes across multiple directories, followed by a subsequent drop of distinct follow-up 'press release' or 'threat' notes within a 30-minute window, indicative of INC Ransom behavior.
Detects unauthorized modification or creation of registry keys under HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\ to maintain persistence for remote access/RMM tools during Safe Mode with Networking. This technique is used by Akira ransomware affiliates to evade EDR and security software.
Detects behavioral patterns associated with the Everest ransomware loader, specifically the execution of a .NET host process from a non-standard parent, potentially indicating process injection, combined with network activity indicative of lateral movement or discovery, such as Wake-on-LAN packets or SMB scanning.
Detects usage of the 'gem' command (install, build, push, publish) that includes naming patterns or specific command strings associated with the GemStuffer supply chain compromise campaign. This targets attempts to introduce malicious dependencies into the environment using RubyGems.
This rule detects the loading of the 'vsstrace.dll' module by processes that are not standard system processes or authorized software. The 'vsstrace.dll' is a library used by the Volume Shadow Copy Service (VSS). Unauthorized or unexpected processes loading this DLL may indicate an attempt to interact with or manipulate volume shadow copies, which is a common behavior for ransomware attempting to inhibit system recovery.


