Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects a single user account performing NTLM network logons (LogonType 3) to 3 or more distinct hosts within a short time period. This pattern is commonly associated with lateral movement techniques such as Pass-the-Hash, where an attacker uses compromised credentials to spread across a network.
Detects access to sensitive Active Directory objects, such as the Domain Admins group or other privileged accounts, as identified by specific GUIDs in Windows Event ID 4662. This event is generated when an object in Active Directory is accessed, and monitoring these specific GUIDs can indicate an adversary attempting to perform reconnaissance or modify sensitive directory objects.
Detects the use of rundll32.exe or regsvr32.exe to execute code via remote scripts, COM scriptlets, or JavaScript. This technique is often used in fileless malware or to bypass execution policies by loading scripts directly from a URL or local file.
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to inhibit system recovery by deleting shadow copies, backup catalogs, or disabling automatic recovery features. This behavior is commonly observed in ransomware attacks.
This rule detects attempts to impair or disable security defenses on Windows systems. It specifically monitors for three categories of malicious behavior: PowerShell-based AMSI (Antimalware Scan Interface) bypass techniques, commands to stop security-related services (e.g., Windows Defender, SentinelOne, CrowdStrike Falcon), and the use of 'reg' or 'PowerShell' to modify registry keys associated with disabling antivirus or real-time monitoring.
Detects instances where a signed executable loads an unsigned, invalid, or revoked DLL that shares the same base filename, located outside of standard Windows system directories (System32, SysWOW64, WinSxS). This behavior is characteristic of DLL search-order hijacking and side-loading attacks often employed by loaders and malware such as Cobalt Strike.
Detects Active Directory Certificate Services (AD CS) certificate requests that include a Subject Alternative Name (SAN) or custom altname attribute, specifically those enabling client authentication. This pattern is commonly associated with the ESC1 privilege escalation technique, where an adversary requests a certificate that impersonates another user or machine account.
Detects Kerberos TGT and service ticket requests that utilize deprecated or weak encryption types (RC4/DES) often associated with Golden Ticket attacks, specifically in environments where AES is mandated. The rule groups these events by user, service, and IP address to identify potential anomalies indicative of credential forgery.
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
The following analytic detects process injection into Notepad.exe using Sysmon EventCode 10. It identifies suspicious GrantedAccess requests (0x40 and 0x1fffff) to Notepad.exe, excluding common system paths like System32, Syswow64, and Program Files. This behavior is often associated with the SliverC2 framework by BishopFox. Monitoring this activity is crucial as it may indicate an initial payload attempting to execute malicious code within Notepad.exe. If confirmed malicious, this could allow attackers to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment.
The following analytic detects attempts to read LSASS memory, indicative of credential dumping.
It leverages Sysmon EventCode 10 and checks for "PROCESS_VM_READ" with query information access on lsass.exe.
It leverages Sysmon EventCode 10 and checks for "PROCESS_VM_READ" with query information access on lsass.exe.
The following analytic detects an uncommon process requesting full access rights to winlogon.exe, which may indicate Rubeus exporting Kerberos tickets from memory.
It leverages Sysmon EventCode 10 and checks for full-access rights, specifically the value 0x1f3fff.
It leverages Sysmon EventCode 10 and checks for full-access rights, specifically the value 0x1f3fff.
The following analytic detects duplicate-handle and query-limited-information access to winlogon.exe from an uncommon or public source path.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
The following analytic detects possible credential dumping by identifying suspicious process access to LSASS with credential-dumping-related call traces.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_LIMITED_INFORMATION (0x1000) and PROCESS_DUP_HANDLE (0x40).
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_LIMITED_INFORMATION (0x1000) and PROCESS_DUP_HANDLE (0x40).
The following analytic detects a process requesting PROCESS_TERMINATE access to Lsass.exe.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_TERMINATE (0x1).
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_TERMINATE (0x1).
The following analytic detects WMI token impersonation by identifying `wmiprvse.exe` requesting the query, VM, and duplicate-handle rights associated with WMI process access.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_INFORMATION (0x400), PROCESS_QUERY_LIMITED_INFORMATION (0x1000), PROCESS_VM_OPERATION (0x8), PROCESS_VM_READ (0x10), PROCESS_VM_WRITE (0x20), PROCESS_DUP_HANDLE (0x40), and PROCESS_ALL_ACCESS (0x1f3fff).
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_INFORMATION (0x400), PROCESS_QUERY_LIMITED_INFORMATION (0x1000), PROCESS_VM_OPERATION (0x8), PROCESS_VM_READ (0x10), PROCESS_VM_WRITE (0x20), PROCESS_DUP_HANDLE (0x40), and PROCESS_ALL_ACCESS (0x1f3fff).
The following analytic detects email files (.pst or .ost) being created outside the standard Outlook directories.
It leverages the Endpoint.Filesystem data model to identify file creation events and filters for email files not located in "C:\Users\*\My Documents\Outlook Files\*" or "C:\Users\*\AppData\Local\Microsoft\Outlook*".
This activity is significant as it may indicate data exfiltration or unauthorized access to email data.
If confirmed malicious, an attacker could potentially access sensitive email content, leading to data breaches or further exploitation within the network.
It leverages the Endpoint.Filesystem data model to identify file creation events and filters for email files not located in "C:\Users\*\My Documents\Outlook Files\*" or "C:\Users\*\AppData\Local\Microsoft\Outlook*".
This activity is significant as it may indicate data exfiltration or unauthorized access to email data.
If confirmed malicious, an attacker could potentially access sensitive email content, leading to data breaches or further exploitation within the network.
The following analytic detects the creation of an lsass.exe process dump using Windows Task Manager.
It leverages Sysmon EventID 11 to identify file creation events where the target filename matches *lsass*.dmp.
This activity is significant because creating an lsass dump can be a precursor to credential theft, as the dump file contains sensitive information such as user passwords.
It leverages Sysmon EventID 11 to identify file creation events where the target filename matches *lsass*.dmp.
This activity is significant because creating an lsass dump can be a precursor to credential theft, as the dump file contains sensitive information such as user passwords.
The following analytic detects unauthorized access to Outlook credentials stored in the Windows registry.
It leverages Windows Security Event logs, specifically EventCode 4663, to identify access attempts to registry paths associated with Outlook profiles.
This activity is significant as it may indicate attempts to steal sensitive email credentials, which could lead to unauthorized access to email accounts.
If confirmed malicious, this could allow attackers to exfiltrate sensitive information, impersonate users, or execute further unauthorized actions within Outlook, posing a significant security risk.
It leverages Windows Security Event logs, specifically EventCode 4663, to identify access attempts to registry paths associated with Outlook profiles.
This activity is significant as it may indicate attempts to steal sensitive email credentials, which could lead to unauthorized access to email accounts.
If confirmed malicious, this could allow attackers to exfiltrate sensitive information, impersonate users, or execute further unauthorized actions within Outlook, posing a significant security risk.
Page 229 of 1871

