Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects anomalous network connections initiated by a node.exe process spawned by npm.exe within 2 minutes of a lifecycle script (preinstall or postinstall) execution. This behavior is indicative of malicious dependency installation where a compromised package attempts to exfiltrate data or fetch additional payloads immediately upon installation.
Detects anomalous network connections initiated by a node.exe process spawned by npm.exe within 2 minutes of a lifecycle script (preinstall or postinstall) execution. This behavior is indicative of malicious dependency installation where a compromised package attempts to exfiltrate data or fetch additional payloads immediately upon installation.
Detects anomalous network connections initiated by a node.exe process spawned by npm.exe within 2 minutes of a lifecycle script (preinstall or postinstall) execution. This behavior is indicative of malicious dependency installation where a compromised package attempts to exfiltrate data or fetch additional payloads immediately upon installation.
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
This rule detects modifications to the security descriptors (ACLs) of sensitive Active Directory objects, specifically targeting additions of powerful rights like GenericAll, GenericWrite, WriteDacl, or ForceChangePassword. Monitoring these changes on privileged objects such as Domain Admins, Enterprise Admins, and Domain Controllers is critical for detecting potential privilege escalation or persistence efforts.
Detects the assignment of SeDebugPrivilege or SeImpersonatePrivilege to a non-SYSTEM account, followed by the execution of a new process from common service parents (spoolsv.exe, w3wp.exe, dllhost.exe) within the same logon session. This behavior is indicative of privilege escalation attempts using local potato-style exploits (e.g., PrintSpoofer, JuicyPotato) that leverage service tokens for impersonation.
Detects the execution of control.exe or rundll32.exe with command line arguments pointing to .cpl files located in non-standard, user-writable directories such as Temp, AppData, Downloads, or Users/Public. This is a common technique used by adversaries to proxy execution of malicious payloads while bypassing standard path restrictions.
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
Detects execution of the Microsoft .NET utility InstallUtil.exe with command-line arguments typically used to execute arbitrary code or bypass application whitelisting. The rule monitors for common bypass switches such as /logfile, /LogToConsole=false, or /U, while filtering out executions from standard Windows directories to identify potential malicious usage of this signed binary proxy.
Detects the execution of Regsvcs.exe or Regasm.exe, which are trusted Windows .NET binaries, from non-standard or user-writable directories (such as Temp, AppData, Downloads, or User profiles). Adversaries often abuse these binaries to proxy the execution of arbitrary malicious code (DLLs) by bypassing application control policies.
Detects unauthorized access or decryption attempts related to Group Policy Preferences (GPP) files stored in SYSVOL. Adversaries often target these XML files to extract embedded 'cpassword' attributes, which can be decrypted using publicly known keys to obtain plain-text administrative credentials.
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
Detects outbound network connections to known Tor SOCKS (9050, 9150) or OR (9001, 9051) ports initiated by processes other than standard, authorized Tor client binaries. This is indicative of potential C2 traffic obfuscation or unauthorized use of the Tor network within the environment.
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
Page 223 of 1871

