Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
Detects network communication to domains and specific file paths associated with the MacSync macOS stealer, which is used for malware dropper delivery and command-and-control (C2) operations. The rule monitors DeviceNetworkEvents for indicators such as specific malicious URLs, iCloud path abuse, and C2 infrastructure interaction.
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
Detects the execution of zsh with potentially suspicious command-line arguments (e.g., usage of curl, pipes, or osascript) occurring within a 15-minute window of network activity connecting to iCloud CalDAV servers. This behavior pattern may indicate unauthorized data access or exfiltration via legitimate cloud services.
Detects modifications to the .zshrc configuration file followed by shell commands interacting with the file, or the execution of commands that source the .repair-run script within a shell environment. This pattern is indicative of potential persistence mechanisms where an adversary modifies startup scripts to maintain access or execute malicious code upon shell initialization.
This rule detects modifications or creation of Git hooks ('pre-commit', 'post-checkout') within local repository directories. Attackers can leverage these hooks as an execution trigger for arbitrary code whenever standard Git actions occur, facilitating persistence or privilege escalation on compromised developer machines.
Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
This rule identifies Linux-based devices that are vulnerable to specific security flaws tracked under CVE-2026-64507 and CVE-2026-64508. It correlates vulnerability assessment data with device inventory to highlight exposed systems.
Detects repeated, silent authentication events in Microsoft 365 where MFA challenges are absent, consistent with the use of stolen session or refresh tokens (e.g., EvilTokens) to maintain persistent, unauthorized access to user accounts.
This rule monitors for the installation of specific known-malicious or suspicious NPM packages that are commonly used in supply chain attacks. It identifies the execution of npm (or node) commands to install or add packages explicitly listed as malicious by security research, which may indicate a supply chain compromise or an attempt to introduce unauthorized code into the development environment.
Detects the presence of specific Go build path metadata associated with the sckit Go implant, including modules and internal package structures, within an executable or file.
This rule detects outbound network beaconing from the SCKit malware to known command-and-control (C2) domains hosted on skyleen.fr or to a specific malicious IP address (139.84.223.178). The rule monitors both TLS SNI indicators in HTTPS traffic and direct IP connections to identify compromised hosts communicating with the attacker's infrastructure.
Detects the creation of a malicious GitHub Actions workflow file named 'runtime-update.yml', a known tactic used by the Sckit supply-chain worm. The worm injects this workflow to automate persistence and further propagation of the Go-based implant within CI/CD pipelines.
Detects the creation of a 'ca-roots.pem' file within a hidden '.sckit' directory on Linux systems. This behavior is associated with the 'sckit' supply-chain malware (e.g., delivered via malicious npm packages like @memtensor/memos-cloud-openclaw-plugin), which uses this bundled certificate to enable HTTPS Command and Control (C2) communication in environments where standard system CA stores are unavailable.
This rule monitors application, build system, and dependency scanning logs for references to known-malicious versions of the @memtensor/memos-cloud-openclaw-plugin (npm) and MemoryOS (PyPI) packages. These versions contain the sckit Go worm and are associated with automated supply chain attacks involving the reuse of stolen credentials, indicated by the 'exact-ref-one-use-NPM_TOKEN' marker.
Detects npm package publish events that lack 'gitHead' provenance metadata. The absence of this field indicates that the package was likely published from a developer's local machine rather than through an authorized CI/CD pipeline, a technique used in supply chain attacks to bypass CI-gated controls.
Detects the execution of the sckit Go implant, linked to the MemTensor supply chain compromise, during its host-profiling stage. The rule monitors for the 'sckit' binary being executed with 'stage0' and '--config64' command-line arguments, or being spawned by legitimate runtime interpreters like Node.js or Python, indicating an attempt to profile host information (timezone, language, privileges) and subsequent self-deletion.
Detects instances where a Google Cloud Config Connector (KCC) service account performs a SetIamPolicy operation that grants high-privilege roles (roles/owner or roles/resourcemanager.organizationAdmin) at the organization or folder scope. This activity often indicates an out-of-band configuration change, a compromised CI/CD pipeline, or an unauthorized escalation, as legitimate KCC changes should be tracked via GitOps records.


