Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
KQL Query from file: Network detection - C2 domains and static key
KQL Query from file: Network detection - C2 domains and static key
This rule detects the presence of the malicious 'pdf-para-texto@extensao.local' Firefox extension on disk. This extension is known to perform browser-based credential interception by patching the WebAuthn PublicKeyCredential interface at document_start on Google-related domains to facilitate account takeover.
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
Detects a multi-stage infection chain involving communication with known malicious infrastructure ('mnoskemp.beer'), staging and extraction of password-protected archives using '7za.exe' in temporary directories, installation of a spoofed OBS Studio MSI package, and subsequent DLL side-loading of malicious libraries (e.g., 'obs.dll', 'WSql-2.dll') by the 'obs64.exe' process when initiated from outside legitimate installation paths.
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
Detects the use of the 'Add-MpPreference' PowerShell cmdlet with the '-ExclusionPath' parameter, which is used to add file, folder, or extension exclusions to Microsoft Defender. Attackers frequently use this technique to prevent security software from scanning or detecting malicious files or directories.
Detects the execution of PowerShell with encoded commands originating from scripting engines wscript.exe or cscript.exe. The command line contains indicators of malicious activity such as references to external domains, archive expansion, or specific executable payloads.
Detects the execution of a process named 'msedge.exe' from the 'ProgramData\Microsoft\Windows\Telemetry' directory. Legitimate Microsoft Edge executables do not run from this location, suggesting an attempt to masquerade as the legitimate browser to bypass security controls or evade detection.
This rule identifies the execution or presence of files matching a known list of MD5 hashes associated with malicious activity. By monitoring file metadata, this rule flags instances where specific identified threat files are present on the system.
This rule detects processes flagged by SentinelOne's behavioral engine with an 'Evasion' indicator. Specifically, this captures behaviors where a process performs manual module or function export enumeration (such as traversing the PEB Ldr linked list or parsing the EAT) to resolve API addresses, a technique often used to avoid standard dynamic-resolution APIs like LoadLibrary or GetProcAddress in order to bypass EDR API hooking.
This rule detects unauthorized or suspicious processes (like Python scripts or random executables) accessing Telegram Desktop's local 'tdata' directory, which contains user session information, and simultaneously exhibiting network activity directed towards Telegram API domains. This behavior is highly indicative of infostealer activity, where a malicious process attempts to harvest local Telegram session data for exfiltration.
This rule detects modifications to Microsoft Defender antivirus exclusions. Adversaries often add paths or files to the exclusion list to prevent the detection of malicious tools or staging folders during cyberattacks. The rule monitors both command-line execution of PowerShell (Add-MpPreference/Set-MpPreference) and direct registry modifications related to Windows Defender paths.
Detects the HEAVYGRAM second-stage implants 'RuntimeSSH.exe' or 'winappx.exe' establishing persistence by adding entries to Windows Registry Run or RunOnce keys.
Page 231 of 1871

