Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
KQL Query from file: ClickFix – Suspicious Persistence Scheduled Task
KQL Query from file: ClickFix – Suspicious User Run Key Persistence
KQL Query
KQL Query from file: ClickFix – PowerShell Launching MSI from Temp
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
Detects two suspicious Kerberos activity patterns indicative of potential credential theft or reconnaissance: 1) A single account requesting tickets for multiple services or across multiple hosts in a short duration, which may indicate automated credential harvesting such as Kerberoasting; 2) The use of RC4 encryption (0x17) for Kerberos tickets, which is an older, weaker protocol and may indicate a forced downgrade attack to facilitate offline password cracking.
This rule detects the creation of potentially malicious script or executable files (.bat, .ps1, .exe, .vbs) within the Windows Startup folder. It triggers when these files are created by processes typically used for automation or development (dotnet, python) or processes utilizing specific semantic/download-related command lines. The rule further correlates this activity with the presence of PowerShell commands indicative of script downloading or code execution (e.g., IEX, DownloadString) by the same device within the same timeframe, suggesting persistent execution of potentially malicious code.
Detects the execution of pypykatz or Python scripts invoking pypykatz commands to perform credential dumping, specifically targeting LSASS memory or minidump files.
Detects a process initiating a memory dump of lsass.exe (using --dump arguments) followed within 15 minutes by the creation of a hexadecimal-named .tmp file in the Windows\Temp directory. This behavioral pattern is characteristic of credential dumping using reflected cloning or similar techniques, followed by the staging of obfuscated or encrypted minidump data for exfiltration.
This rule detects LSASS credential dumping attempts by correlating the execution of a dump command (via process command line) with the subsequent creation of a temporary file in the Windows Temp directory. The rule is specifically designed to bypass evasion techniques that introduce randomized delays between the LSASS process access and the file write operation by utilizing a 30-minute join window.
Detects the pidclone-style LSASS credential dumper that clones the target process into a suspended state, mirrors its memory, generates a minidump, and writes an XOR-encrypted copy of the dump to a randomized filename under Windows\Temp
Detects a sequence of events indicative of LSASS memory dumping where a process opens a handle to lsass.exe and subsequently creates a uniquely named temporary file (16-character hexadecimal filename) in the Windows Temp directory within a short timeframe. This behavior is often associated with the obfuscated flushing of a stolen memory dump to disk to evade signature-based detection.
Detects the execution of pypykatz or Python scripts invoking pypykatz commands to perform credential dumping, specifically targeting LSASS memory or minidump files.
Detects command-line activity indicative of attempts to dump LSASS memory after performing in-memory unhooking or bypassing of security monitoring DLLs (ntdll.dll, amsi.dll, win32kbase.sys). This behavior is characteristic of adversaries attempting to harvest credentials while evading EDR/AV visibility.
Detects a process initiating a memory dump of lsass.exe (using --dump arguments) followed within 15 minutes by the creation of a hexadecimal-named .tmp file in the Windows\Temp directory. This behavioral pattern is characteristic of credential dumping using reflected cloning or similar techniques, followed by the staging of obfuscated or encrypted minidump data for exfiltration.
This rule detects LSASS credential dumping attempts by correlating the execution of a dump command (via process command line) with the subsequent creation of a temporary file in the Windows Temp directory. The rule is specifically designed to bypass evasion techniques that introduce randomized delays between the LSASS process access and the file write operation by utilizing a 30-minute join window.
Detects outbound HTTP POST requests associated with the Telepuz modular loader. The rule monitors for specific URI patterns, request body parameters, and suspicious User-Agent strings indicative of PowerShell or MSHTA command-and-control communication.



