Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where AI-assisted development tools (such as Claude, Codex, Copilot, or Gemini) initiate command-line processes (e.g., shells, interpreters, or network utilities) with arguments indicative of credential access, reconnaissance, or sensitive file interactions.
Detects the execution of destructive SQL commands (e.g., DROP, TRUNCATE, mass DELETE) via common command-line database clients. These patterns are often observed when threat actors attempt to destroy forensic evidence or interrupt database availability immediately following unauthorized data exfiltration.
Detects web or application server processes (Apache, Nginx, IIS, Tomcat, PHP) spawning command interpreters or scripting engines. This behavior is indicative of a post-exploitation activity where an attacker executes commands following a remote code execution exploit against the web application.
Detects malicious JavaScript injection on e-commerce checkout or payment pages designed to harvest sensitive payment card information (PAN, CVV, expiry) and exfiltrate the stolen data to an external endpoint. This behavior is indicative of a digital credit card skimmer (e.g., Magecart style) deployed following a compromise of the web application.
This rule detects Terraform CLI activity interacting with suspicious domains or modules, specifically targeting known repositories or namespaces (e.g., gocommunity.io, gogets.dev). It monitors for Terraform initialization or application patterns referencing these domains in process command lines, as well as the creation of Terraform provider files within these specific namespaces. This behavior is indicative of potential supply chain compromise involving malicious Terraform modules or dependencies.
This rule detects when common web server processes or service accounts spawn unexpected interpreter, shell, or reconnaissance tools, which is a common indicator of post-exploitation activity following a successful Remote Code Execution (RCE) attempt.
Detects execution of a specific suspicious executable file masquerading in the Windows Temp directory, coupled with the access of an associated .ini configuration file. This behavior is indicative of AsyncRAT deployment, often involving initial execution or staging of configuration files within volatile user directories.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that involve indicators often associated with malicious behavior, such as targeting temporary or publicly writable directories ('appdata', 'temp', 'programdata') or employing suspicious command-line flags (e.g., encoded commands, highest privileges, or execution on system startup).
Detects Kerberoasting activity by identifying a high volume of RC4-encrypted (0x17) Kerberos Service Ticket (TGS) requests from a single user account against multiple distinct service principal names (SPNs) within a short timeframe. This behavior is highly indicative of automated credential harvesting tools such as Rubeus or Impacket.
This rule detects potential Pass-the-Hash lateral movement by identifying NTLM network logons (Event ID 4624, LogonType 3) on a host that lack a preceding interactive (LogonType 2, 10) or Kerberos-authenticated logon, coupled with subsequent access to sensitive administrative shares (Event ID 5140) by the same user account.
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI). This rule monitors for command-line arguments indicative of reflection-based patching of AmsiUtils and forced AmsiScanBuffer failures, as well as registry modifications to AMSI providers.
Detects the creation of new Windows services using sc.exe or PowerShell where the binary path is located in common user-writable or temporary directories (e.g., Temp, AppData, ProgramData), or where the service name mimics legitimate Windows system services, a technique often used for persistence or lateral movement (e.g., PsExec).
This rule detects modifications to Windows Registry run keys and startup folder locations that are commonly used for persistence. It specifically flags when entries point to scripts, interpreted binaries, or files located in directories often used by attackers to hide malicious payloads (e.g., AppData, Temp, ProgramData).
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to delete volume shadow copies, backup catalogs, or disable system recovery features. The rule further correlates this activity with preceding mass file activity to identify potential ransomware or destructive attack behavior.
Detects the execution of PowerShell with common obfuscation or download flags (e.g., -EncodedCommand, IEX, DownloadString) specifically when the parent process is a common attack vector entry point such as Office applications, web browsers, or script hosts (wscript/cscript/mshta). This behavior is characteristic of phishing-based execution chains.
Detects anomalous Kerberos TGS (Ticket Granting Service) requests using weak RC4-HMAC (0x17) encryption. The rule looks for accounts requesting multiple service tickets for distinct Service Principal Names (SPNs) within a short time window, which is a common behavior pattern for tools like Rubeus or GetUserSPNs.py during the credential-harvesting phase of a Kerberoasting attack.
This rule detects potential AS-REP Roasting activity by monitoring Windows Event ID 4768 (TGT Request). It identifies multiple Kerberos AS-REQ requests from a single IP address within a 10-minute window, where the PreAuthType is 0 (indicating no pre-authentication) and the encryption type is RC4 (0x17 or 23). This behavior is characteristic of enumeration and exploitation tools such as Rubeus or Impacket's GetNPUsers.py, which attempt to obtain extractable TGTs for accounts that do not require Kerberos pre-authentication.
Detects anomalous NTLM network logons (Logon Type 3) where the same user account authenticates to multiple distinct hosts within a short time window. This behavior is correlated with NTLM validation (4776) events to identify potential Pass-the-Hash activity used for lateral movement.
Detects the creation of scheduled tasks using schtasks.exe or Event ID 4698 that involve suspicious binaries (e.g., powershell, mshta), execution from user-writable directories, or tasks configured to run with SYSTEM privileges, which are common indicators of persistence establishment.
Detects anomalous Kerberos ticket requests characteristic of Golden Ticket attacks. These forged tickets are created offline using the KRBTGT account hash, bypassing legitimate KDC TGT issuance, and frequently exhibit default Mimikatz artifacts such as RC4 encryption or extended ticket lifetimes.
This rule detects the creation of new Windows services (Event IDs 7045 and 4697) where the service binary path points to potentially suspicious locations such as user profiles, temp directories, program data, or common command interpreters. This pattern is frequently used by adversaries for persistence mechanisms or to deploy malicious drivers/tools.
Page 227 of 1871


