Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects unauthorized access to the Directory Replication Service (DRS) using Event ID 4662. The rule looks for access requests to sensitive Active Directory replication objects (GUIDs 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 and 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) initiated by accounts other than Domain Controller machine accounts, which is a signature behavior of tools like Mimikatz lsadump::dcsync or Impacket's secretsdump.py.
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin) or PowerShell cmdlets to delete Volume Shadow Copies or backup catalogs. This behavior is commonly associated with ransomware attempts to prevent system recovery.
This rule monitors for persistence mechanisms by detecting modifications to Windows Registry Run/RunOnce keys or the creation of files within the Windows Startup folder. It specifically flags instances where the executable or script being registered resides in high-risk directories such as Temp, AppData, or Downloads, and correlates these events with recent process execution to confirm the persistence activity.
This rule detects potential Windows token manipulation by correlating logon events containing sensitive privileges (SeDebugPrivilege/SeImpersonatePrivilege) with subsequent process creation events under a different user context within a short timeframe. It further validates the activity by incorporating Sysmon Event ID 10 alerts that identify process access patterns commonly associated with token duplication or impersonation techniques used in post-exploitation frameworks like Cobalt Strike.
Detects the issuance or renewal of Kerberos Ticket-Granting Tickets (TGT) (Event IDs 4768 and 4769) where the ticket lifetime or renewal duration exceeds standard Windows domain Kerberos policy defaults (typically 10 hours for lifetime and 7 days for renewal). Deviations from these standard thresholds are common indicators of forged Golden Tickets created using an exfiltrated KRBTGT hash.
Detects the execution of the rclone utility (including renamed binaries) using command-line arguments consistent with data exfiltration or synchronization (copy, sync, move) that is followed by network communication to known cloud storage providers commonly abused for staging and exfiltration in ransomware attacks.
Detects active attempts to disable or interfere with security products, including EDR agents and antivirus software. The rule monitors for the use of 'sc.exe' to stop or reconfigure services, 'taskkill' to terminate security-related processes, and PowerShell commands utilizing 'Set-MpPreference' to modify Windows Defender real-time protection settings. These actions are frequently observed as a precursor to ransomware deployment or other malicious activities designed to evade detection.
Detects potential lateral movement by monitoring user accounts performing interactive RDP logons (LogonType 10) to multiple distinct internal hosts within a 15-minute window. Additionally, identifies RDP logons occurring outside of standard business hours (before 6 AM or after 8 PM), a pattern often associated with human-operated ransomware activity.
This rule detects potential ransomware activity by correlating the execution of native Windows utilities used to inhibit system recovery (vssadmin, wmic, wbadmin, bcdedit) followed by a high volume of file modification events on the same host within a 15-minute window.
Detects two distinct methods of living-off-the-land proxy execution: first, MSBuild.exe spawning network connections after executing inline tasks defined in XML project files; second, Regsvr32.exe performing 'Squiblydoo' execution by loading COM scriptlets from remote URLs.
Detects command-line execution patterns indicative of Anti-Malware Scan Interface (AMSI) bypass attempts. The rule looks for attempts to manipulate internal .NET AmsiUtils fields, modify AmsiScanBuffer, or utilize VirtualProtect against amsi.dll memory regions, all of which are common techniques employed by malicious loaders to evade script-based detection.
Detects Kerberos service ticket requests (Event ID 4769) that utilize weak RC4 encryption (0x17). This behavior is characteristic of Kerberoasting, where attackers request service tickets for service accounts in order to perform offline brute-force attacks to recover the service account password. The rule filters out machine account requests and focuses on standard user or service account requests.
Detects suspicious PowerShell execution patterns involving encoded commands, hidden window styles, or common download cradles combined with code obfuscation techniques. This rule monitors PowerShell ScriptBlock Logging (Event ID 4104) for combinations of indicators often used by threat actors to evade detection, such as Base64-encoded strings, hidden execution flags, network download utilities, and script obfuscation techniques.
Detects Kerberos service ticket requests (Event ID 4769) that utilize weak RC4 encryption (0x17). This behavior is characteristic of Kerberoasting, where attackers request service tickets for service accounts in order to perform offline brute-force attacks to recover the service account password. The rule filters out machine account requests and focuses on standard user or service account requests.
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to delete volume shadow copies, backup catalogs, or disable recovery mechanisms. This behavior is commonly associated with ransomware or destructive attacks attempting to inhibit system recovery.
This rule detects attempts to perform a DCSync attack by monitoring for Windows Event ID 4662 (Object Access) with specific Directory Replication Service (DRS) GUIDs. These GUIDs are used by attackers to request the replication of sensitive data, such as password hashes, from a Domain Controller without having direct access to it. This technique is commonly used by tools like Mimikatz and Impacket's secretsdump to extract credentials from Active Directory.
This rule detects the creation of named pipes with names that match default or commonly customized patterns used by Cobalt Strike Beacons for inter-process communication (IPC) and lateral movement. The detection specifically targets common pipe naming conventions such as those starting with 'msagent_', 'MSSE-', 'postex_', 'status_', and 'mypipe-', which are frequently observed in Cobalt Strike configurations.
Detects common LSASS memory dumping techniques, including suspicious process access rights (EventID 10) and the execution of tools or techniques (EventID 1) such as comsvcs.dll, procdump, taskmgr, or werfault, which are often used to harvest credentials.
Detects the creation of new system services using EventID 7045 where the ImagePath points to suspicious temporary directories, administrative shares (ADMIN$), or utilizes randomly generated service names. This pattern is commonly associated with PsExec-style lateral movement and ransomware staging.
Detects modifications to Windows Registry persistence keys (Run, RunOnce, RunServices, RunServicesOnce) where the referenced executable or script path resides in low-trust locations such as AppData, Temp, or Public directories. This pattern is commonly used by adversaries to establish persistence after initial execution.
Detects suspicious cross-process access patterns targeting trusted system processes (svchost.exe, explorer.exe, notepad.exe) by utilizing broad process access rights (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD). This behavior is characteristic of process injection techniques like process hollowing, often employed by loaders and malware to execute code within the context of a legitimate process.
Page 228 of 1871
