Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
Detects the installation of a potentially malicious root certificate on a host. The rule monitors for common command-line arguments used by 'certutil.exe' to add certificates to the store, use of the 'security' utility for certificate installation on macOS, and the execution of processes referencing 'Localcertificate.zip'.
This rule detects inbound HTTP requests targeting Microsoft Exchange Server that contain the specific headers and patterns associated with the ProxyLogon (CVE-2021-26855) Server-Side Request Forgery (SSRF) vulnerability. It specifically monitors for the presence of the 'X-BEResource' header and malformed request structures used by attackers to bypass authentication.
Detects instances where Google Chrome accesses the camera or microphone without a preceding browser-based user interaction event (such as a mouse click or user input). This can indicate malicious browser extensions or hijacked processes attempting to surreptitiously capture audio or video.
Detects instances where a web browser process (e.g., Chrome, Edge, Firefox) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently associated with malicious 'ClickFix' or 'fake decryption' social engineering campaigns where users are tricked into copying and executing malicious commands into a terminal.
Detects the execution of PowerShell with hidden window styles and encoded commands that perform common post-exploitation activities, such as remote file downloading or expression evaluation via IEX. This is a common pattern for fileless malware delivery and secondary payload execution.
Detects instances where known NetSupport Manager binaries (client32.exe, netsupportmanager.exe, pcicfgnt.exe) are used to perform persistence-related actions, such as creating a new Windows service, adding a scheduled task, or modifying Run/Winlogon registry keys.
Detects browser-based network requests to 'script.google.com'. This can indicate usage of Google Apps Scripts, which are sometimes abused by attackers for Command and Control (C2) infrastructure, data exfiltration, or as a proxy for malicious payloads, by blending in with legitimate Google traffic.
Detects instances where the IIS worker process (w3wp.exe) spawns common command-line or system utilities often used for post-exploitation activities, specifically when command-line arguments contain references to 'MSExchange' or 'Exchange'. This behavior is frequently associated with exploitation attempts against Microsoft Exchange servers, such as the ProxyLogon chain, where a web shell or other malicious script might be used to execute commands via the IIS process.
Detects the creation of a registry value named 'SnapCart' within the Windows Run keys. Adversaries use Run keys to ensure that malicious programs execute automatically upon user login or system startup, establishing persistence on the compromised host.
Detects the creation of Object Manager symbolic links that redirect the Windows Defender 'WD_SCAN' object to a loopback UNC share path. This behavior is indicative of a symlink exploitation technique (ShieldCrash/CVE-2026-69414) used to manipulate Windows Defender or associated scan operations by redirecting them to an adversary-controlled or loopback-hosted target.
Detects indicators of the SparroWocky Trident loader, including specific side-loaded DLLs (winfsp-x64.dll, DukeQt.dll), encrypted payload files with custom magic headers, persistence mechanisms such as specific service names and registry keys, inter-process communication objects (mutexes, events, shared memory), and named pipes used for C2 communication.
Detects camera or microphone access events triggered by Chrome browser processes associated with AI agent contexts (e.g., Gemini, assistant, side panels, or extensions) where no user gesture or active video conferencing application is detected. This behavior is indicative of unauthorized or surreptitious media device usage by browser-based AI integrations.
Detects the execution of known Remote Monitoring & Management (RMM) software on Windows systems. This behavior is frequently abused by threat actors, including Scattered Spider, to maintain persistent access after gaining control via social engineering or identity-based attacks (e.g., vishing-driven credential or MFA resets).
Detects the installation or configuration of a browser extension that combines 'declarativeNetRequest' (network manipulation) and 'content_scripts' (DOM injection) capabilities while targeting sensitive AI-assistant domains such as gemini.google.com, perplexity.ai, opera.com, or claude.ai. This configuration is indicative of potential AI agent hijacking, allowing unauthorized code execution and traffic interception on trusted vendor websites.
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
Page 225 of 1871


