Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects outbound HTTP POST requests associated with the Telepuz modular loader. The rule monitors for specific URI patterns, request body parameters, and suspicious User-Agent strings indicative of PowerShell or MSHTA command-and-control communication.
Detects outbound HTTP POST requests associated with Cicada3301 ransomware affiliate check-in behavior. The rule monitors for a specific 'X-Session-Id' HTTP header and a corresponding 'affiliate_id' parameter within the request body, which are indicative of malicious C2 communication.
Detects outbound network traffic from internal servers to known Remote Monitoring and Management (RMM) platforms (AnyDesk, ScreenConnect, Atera). This activity is often used by adversaries to establish covert command and control (C2) channels and remote access to internal resources.
Detects network activity related to the BEAST ransomware targeting VMware ESXi systems. The rule identifies attempts to stage encryption operations via SSH, including detecting references to known filenames ('encryptor.elf', 'beast_esxi') and the use of the 'vim-cmd' utility to power off virtual machines as part of the preparation for file encryption.
Detects outbound HTTP PUT requests characteristic of data exfiltration associated with Qilin ransomware. The rule monitors for the use of command-line tools like s5cmd or rclone for uploading data, often used during the double extortion phase where stolen data is uploaded to leak sites.
Detects web traffic containing indicators of 'ClickFix' social engineering attacks. These attacks present a fake 'CAPTCHA' or verification prompt to the user and instruct them to copy and paste a malicious script (involving PowerShell or mshta) into their system terminal.
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
Detects a specific SharePoint markup injection technique targeting the EditingPageParser type-check mechanism. An attacker smuggles a 'Register' directive into a crafted WebPartMarkup POST request using the 'publishingribbon' Tagprefix to bypass SafeControl validation.
This rule detects potential post-exploitation activity following a SharePoint XamlServices.Parse() deserialization attack. It monitors the w3wp.exe (IIS worker process) for the loading of suspicious .NET deserialization-related assemblies (e.g., System.Xaml.dll) followed by the execution of a shell process (cmd.exe, powershell.exe, etc.) within a short window, which is indicative of fileless web shell activity.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Detects periodic outbound network connections (beaconing) to rare remote destinations initiated by processes running from non-standard or user-writable locations. The rule calculates the interval coefficient of variation (CV) between successful connections to identify regular, consistent patterns indicative of command and control communication while excluding known legitimate update and service traffic.
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
This rule detects potentially malicious command execution initiated by web browsers (Chrome, Edge, Firefox, Safari, Opera). It identifies scenarios where browsers spawn PowerShell on Windows with encoded command arguments or spawn shells (zsh, bash, sh) on macOS while piping commands retrieved via curl or wget, which is a common pattern for dropper and fileless malware delivery.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
Detects indicators of compromise related to the TraderTraitor (KelpDAO) threat actor, including specific file hashes, malicious process paths, C2 network infrastructure (IPs and domains), and malicious TLS certificates. The rule uses filename-path matching to reduce noise from legitimate macOS binaries.
Detects specific malicious Mach-O binary payloads associated with the Atomic macOS Stealer (AMOS) discovered in the Macfinger ClickFix campaign. The rule uses static file hashes to identify these specific samples.
Detects an outbound network connection initiated by 'rnpkeys.exe' when executing from a non-standard 'ProgramData\keyroll' directory. This behavior is associated with the early stages of a Command and Control (C2) registration sequence, where an encrypted loader initiates network contact before subsequent staged communication.
Detects known components of the Sauron malware, including MSI installers, side-loaded executables (rnpkeys.exe), and malicious DLLs (rnp.dll, tdwp.dll) by matching known SHA-256 file hashes. It also includes a YARA rule for detecting PE binaries containing the string 'Sauron'.
Detects the presence of MSI installer packages associated with the Sauron Loader malware, which stage malicious files (rnpkeys.exe, rnp.dll, and tdwp.dll) into the C:\ProgramData\keyroll directory to facilitate DLL side-loading.


