Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
IOC sweep against network telemetry for confirmed BengalSEO/MayaBot campaign infrastructure: the Hostmaza backend IP (5.101.140.80), Matomo tracking domains (stats.us3.org, us3.my), named MayaBot C2 domains (cus.cam, dll.lat, us99.org), and the ~170-domain Traffic Distribution System redirector fleet used to funnel victims to payload delivery. The source intel report contains no file hashes (MD5/SHA1/SHA256) -- only IPs, domains, and URLs -- so this sweep is IP/domain-only. Note the much larger corpus of single-use lure-page domains (~1,000 additional indicators) is excluded as too high-churn for static embedding.
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
Detects high-volume file download, access, or preview activity originating from known anonymous proxy services. This behavior is indicative of potential data exfiltration or unauthorized mass data collection from cloud storage applications.
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
Detects high-frequency requests directed at common model-serving API endpoints, which may indicate an attacker attempting to perform model extraction or model inversion attacks by repeatedly querying the model to infer its parameters or training data.
Detects malicious shell commands or scripts (e.g., bash, powershell, curl, wget) embedded within HTTP POST request bodies that appear to be AI agent tool-call payloads. This activity is indicative of prompt injection or AI tool-use exploitation attempts designed to execute arbitrary code on the underlying host or container.
This rule detects potential automated subdomain enumeration by monitoring for a high volume of DNS queries (200 or more within 60 seconds) originating from a single host. Such behavior is characteristic of reconnaissance activities used to discover subdomains and map out network infrastructure.
This rule detects high-frequency HTTP 401 Unauthorized responses directed at API endpoints (specifically matching '/v1/') within a short window, which is indicative of an adversary attempting to brute-force or credential-stuff API keys.
Detects instances where a user grants high-privilege permissions (Mail.Read, Files.ReadWrite.All, offline_access) to an OAuth application within 24 hours of a risky sign-in event. This pattern is commonly observed in AiTM (Adversary-in-the-Middle) or consent-phishing attacks designed to establish persistent access to cloud resources.
Detects potential Adversary-in-the-Middle (AiTM) MFA bypass attacks (quishing). The rule correlates receipt of an email containing an image attachment (potential QR code) but no URL, followed by a risky mobile sign-in event from a device that is unmanaged or lacks trust within a two-hour window.
Detects potential Adversary-in-the-Middle (AiTM) activity by identifying successful multi-factor authenticated sign-in events from the same user across different geographic regions and IP addresses within a one-hour timeframe, which is characteristic of session cookie replay attacks.
Detects a sequence of events where a user with a high-risk or compromised sign-in status registers a new device in Entra ID shortly after the event, followed by subsequent sign-ins from that device that bypass multi-factor authentication (MFA) via Conditional Access policies.
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
Detects inbound emails containing malicious QR codes (quishing) or HTML smuggling payloads designed to facilitate credential harvesting (AiTM). The rule identifies suspicious attachments, HTML-based obfuscation (e.g., atob, Blob) in email bodies, and QR-code-themed image attachments, filtering out internal communications.
This rule detects activities indicative of an attacker attempting to establish an adversary-in-the-middle (AiTM) position within an on-premises network. It flags potential NTLM relay attempts (via loopback or invalid workstation indicators) and unauthorized name resolution spoofing (LLMNR/NBT-NS) used to intercept and relay authentication traffic for MFA bypass or credential theft.



