Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects execution of the Microsoft .NET utility InstallUtil.exe with command-line arguments typically used to execute arbitrary code or bypass application whitelisting. The rule monitors for common bypass switches such as /logfile, /LogToConsole=false, or /U, while filtering out executions from standard Windows directories to identify potential malicious usage of this signed binary proxy.
Detects the execution of Regsvcs.exe or Regasm.exe, which are trusted Windows .NET binaries, from non-standard or user-writable directories (such as Temp, AppData, Downloads, or User profiles). Adversaries often abuse these binaries to proxy the execution of arbitrary malicious code (DLLs) by bypassing application control policies.
Detects unauthorized access or decryption attempts related to Group Policy Preferences (GPP) files stored in SYSVOL. Adversaries often target these XML files to extract embedded 'cpassword' attributes, which can be decrypted using publicly known keys to obtain plain-text administrative credentials.
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
Detects outbound network connections to known Tor SOCKS (9050, 9150) or OR (9001, 9051) ports initiated by processes other than standard, authorized Tor client binaries. This is indicative of potential C2 traffic obfuscation or unauthorized use of the Tor network within the environment.
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
This rule detects the execution of a suspicious, specifically named executable (ogftogcyiblzjccmcbnw.exe) originating from a temporary folder, or the creation/access of a related configuration file (kojuyn.ini) within the same temp directory. This pattern is consistent with the delivery and execution of malicious tools like AsyncRAT or similar threats that often use obfuscated filenames and localized configuration files within temporary user paths.
This rule monitors endpoint network events, file operations, and process executions for known malicious indicators (domains and file hashes) associated with Kremlin activity. It detects connections to suspicious remote domains and the existence or execution of specific malicious file hashes.
This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
Page 224 of 1871


