Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects the loading of the 'vsstrace.dll' module by processes that are not standard system processes or authorized software. The 'vsstrace.dll' is a library used by the Volume Shadow Copy Service (VSS). Unauthorized or unexpected processes loading this DLL may indicate an attempt to interact with or manipulate volume shadow copies, which is a common behavior for ransomware attempting to inhibit system recovery.
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
Detects indicators of compromise related to the TraderTraitor (KelpDAO) threat actor, including specific file hashes, malicious process paths, C2 network infrastructure (IPs and domains), and malicious TLS certificates. The rule uses filename-path matching to reduce noise from legitimate macOS binaries.
Remote Scheduled Task Creation via RPC
Cortex XDR
This rule detects the creation of scheduled tasks on a remote host via the Task Scheduler RPC interface (opnum 1, RegisterTask). This interface is commonly abused by lateral movement tools such as Impacket's atexec, SharpTask, and SynkLoader to execute code or establish persistence on a remote system.
Detects a multi-stage loader execution chain, potentially named GHAPPIER, by identifying sequential stages of execution. These stages include initial marker file checks, shell-based command dispatching via curl/wget, renaming and execution of secondary payloads, Node.js-based runtime staging, and the eventual creation of implant artifacts in common paths such as VSCode extensions or hidden directories.
Detects the use of 'terraform init' where the command line arguments reference known typosquatted HashiCorp registry domains. This behavior is indicative of a supply chain attack attempting to pull malicious providers or modules from an adversary-controlled source.
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
This rule monitors network, DNS, and HTTP activity to identify connections to known infrastructure associated with the ClickFix social engineering campaign and Vidar infostealer malware. The rule correlates device network events, HTTP request events, and DNS queries against a list of known malicious domains, IP addresses, and URL patterns used for C2, staging, and lures.
This rule detects potential unauthorized account creation by correlating suspicious administrative activity on network edge devices (VPNs, firewalls) with subsequent local administrator account creation on an internal host within a one-hour window. This behavior is indicative of ransomware affiliates exploiting internet-facing infrastructure to gain initial access and escalate privileges.
Detects multiple methods of tampering with Windows Defender security controls within a short time window. This includes PowerShell commands to modify Defender preferences (e.g., disabling Real-time Monitoring or adding exclusions), modifications to Defender-related registry keys, and attempts to stop or disable the WinDefend service.
Detects processes establishing persistence via Windows Registry 'Run' keys followed by frequent outbound network connections over non-standard ports. This behavior is consistent with the SystemBC/Coroxy SOCKS5 proxy backdoor often utilized by ransomware actors like Ryuk, Conti, BlackBasta, Play, and Rhysida.
Detects persistence mechanisms used by The Gentlemen ransomware, specifically the creation of malicious scheduled tasks (UpdateUser, UpdateSystem, or gentlemen_system) and modification of registry Run keys (GupdateS or GupdateU). The rule also monitors for the presence of the operator password string 'G7Vz9eyG' within command line arguments.
Detects attempts to terminate security-related processes (AV/EDR) using common administrative tools including taskkill.exe, wmic.exe, and PowerShell Stop-Process. This behavior is frequently observed during the pre-encryption phase of ransomware attacks, such as Nova and Gentlemen, to evade detection.
Detects ClickFix-style social engineering attacks where a user is tricked into manually executing a PowerShell command. The command typically utilizes Invoke-RestMethod to fetch a remote payload and Invoke-Expression to execute it in memory, bypassing execution policies. This behavior is commonly associated with campaigns like SmartApeSG and DeepLoad.
Detects the DeepLoad malware staging process injection by spawning trusted Windows binaries (LockAppHost.exe, makecab.exe, or Magnify.exe) in a suspended state from an unauthorized parent process. This behavior is indicative of an APC-based injection sequence where malicious code is written into the suspended process before execution.
Detects the execution of PowerShell scripts 'first.ps1' and 'main1.ps1', which are components of a known credential phishing toolset. This tool displays a fake Windows Update dialog to trick users into providing their credentials, which are then exfiltrated via SMB, DNS, or HTTP.
Detects reconnaissance and persistence behaviors associated with the Akira ransomware attack chain, specifically the execution of the Cloudflare Tunnel daemon for remote access or the creation/modification of local user accounts via standard Windows tools.
KQL Query from file: Detect Docker API activity on port 2375
KQL Query from file: Carbonato: C2 Communication Detected
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001




