Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects suspicious PowerShell command-line activity involving the use of encoded, obfuscated, or stealth-focused flags, as well as common patterns associated with fileless payload delivery and execution.
Detects the creation of Windows scheduled tasks using schtasks.exe that exhibit high-risk indicators, such as targeting temporary or user-writable directories (Temp, AppData), setting high-privilege execution flags, or utilizing PowerShell with encoded payloads. These behaviors are commonly associated with the installation of persistence mechanisms by threat actors.
Detects the creation of permanent WMI event subscriptions which can be used by adversaries to establish persistence by triggering malicious code execution upon specific system events. The rule monitors Sysmon events 19, 20, and 21 as well as Microsoft-Windows-WMI-Activity logs for modifications involving Event Filters, Consumers, and Bindings, specifically looking for CommandLineEventConsumer or ActiveScriptEventConsumer.
Detects the creation or modification of Windows Registry Run/RunOnce keys or files within the Startup folder where the target command path is deemed suspicious (e.g., temp directories, ProgramData), utilizes known LOLBins, or contains common obfuscation flags (e.g., -enc, IEX, -w hidden) frequently associated with persistence mechanisms.
Detects the creation of new services consistent with PsExec or PAExec lateral movement. The rule monitors for Windows Event IDs 7045 and 4697 where the service name uses common PsExec/PAExec naming conventions or the image path points to suspicious locations such as admin shares or temporary directories often used by these tools for binary staging.
Detects Kerberos service ticket requests (TGS-REQ) using RC4 encryption (etype 0x17) and specific ticket options (0x40810000), which are commonly associated with Kerberoasting attacks. This rule filters out service accounts (ending in $) to reduce noise, as these legitimate account types frequently request tickets.
Detects the abuse of the Windows built-in utility 'certutil.exe' to download files or decode obfuscated payloads. Attackers frequently use certutil as a Living off the Land Binary (LOLBin) to bypass security controls by leveraging its native capabilities for file transfer (via URL cache) and base64 or hexadecimal decoding.
Detects a single account requesting an abnormally large number of Kerberos service tickets (Event ID 4769) using weak RC4 encryption (0x17) within a short window. This pattern is characteristic of Kerberoasting attacks, where an adversary requests service tickets for offline password cracking.
Detects the execution of mshta.exe with suspicious command-line arguments that indicate the loading of remote HTML Applications (HTA) via URLs or inline scripts (javascript/vbscript). This behavior is often indicative of fileless malware execution and living-off-the-land techniques to bypass security controls.
Detects the use of PowerShell to download content from an external URL and immediately execute it in memory using common download cradles (e.g., Net.WebClient, IWR) combined with execution commands like IEX (Invoke-Expression). This is a common pattern for fileless malware delivery and post-exploitation activity.
Detects attempts to disable Windows Defender features via PowerShell, terminate critical security services using administrative tools like sc.exe or net.exe, or inject/patch AMSI (Antimalware Scan Interface) within a process context to evade detection.
Detects the creation or abuse of Volume Shadow Copies specifically to access the NTDS.dit file or the SYSTEM registry hive, a common technique for offline Active Directory credential dumping.
Detects instances where common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) spawn child processes that are typically associated with command interpretation, scripting, or LOLBins (Living Off the Land Binaries). This behavior is often indicative of malicious macro execution, exploit payloads, or obfuscated command execution originating from malicious documents.
Detects potential Pass-the-Hash (PtH) activity by monitoring Windows Security Event ID 4624 (Logon). The rule specifically targets logon type 9 (NewCredentials) combined with specific process/package names indicative of tools like Mimikatz, or anomalous NTLM network logons (logon type 3) that are not anonymous.
Detects instances where AI-assisted development tools (Claude, Codex, Copilot, Gemini) are used to execute git checkout commands. The rule filters for non-interactive parent processes to identify potentially automated or background execution of git operations by these development assistants.
Detects instances where AI-assisted development tools (Claude, Codex, Copilot, Gemini) are used to execute git checkout commands. The rule filters for non-interactive parent processes to identify potentially automated or background execution of git operations by these development assistants.
Detects instances where AI-assisted development tools (such as Claude, Codex, Copilot, or Gemini) initiate command-line processes (e.g., shells, interpreters, or network utilities) with arguments indicative of credential access, reconnaissance, or sensitive file interactions.
Detects the creation or abuse of Volume Shadow Copies specifically to access the NTDS.dit file or the SYSTEM registry hive, a common technique for offline Active Directory credential dumping.
Detects instances where common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) spawn child processes that are typically associated with command interpretation, scripting, or LOLBins (Living Off the Land Binaries). This behavior is often indicative of malicious macro execution, exploit payloads, or obfuscated command execution originating from malicious documents.
Detects potential Pass-the-Hash (PtH) activity by monitoring Windows Security Event ID 4624 (Logon). The rule specifically targets logon type 9 (NewCredentials) combined with specific process/package names indicative of tools like Mimikatz, or anomalous NTLM network logons (logon type 3) that are not anonymous.
Detects processes opening lsass.exe with high-risk access rights consistent with credential dumping (Sysmon EventID 10), including known dumping tool patterns such as procdump or rundll32 invoking the comsvcs.dll MiniDump export.
Page 226 of 1871

