Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the use of rundll32.exe to execute comsvcs.dll's MiniDump functionality against the LSASS process, a common technique for dumping credentials. The rule includes behavioral correlation by identifying the same user account executing this pattern on multiple devices within a one-hour window.
Detects unauthenticated attempts to access Adobe Commerce/Magento REST API endpoints. This rule specifically looks for HTTP GET requests containing /rest/ and /V1/ paths without an Authorization header, which may indicate an attempt to exploit CVE-2026-71362.
Detects incoming HTTP POST requests to the Zimbra OnlyOffice document handler containing path traversal sequences (e.g., '..'). This pattern is indicative of an attempt to exploit CVE-2026-93643 by manipulating document save or callback paths to access unauthorized files on the server.
Detects attempts to exploit a buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series switches. The rule monitors for oversized POST requests directed at CGI scripts on the device's web management interface.
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
This rule detects HTTP POST requests to the Apache Qpid Broker-J Management API that include a pre-set JSESSIONID in the cookie header during a login operation, indicating an attempt to exploit CVE-2026-92609 via session fixation.
Detects attempts to access administrative or configuration endpoints on Cisco Identity Services Engine (ISE) without providing valid authentication headers, cookies, or authorization tokens. This behavior is indicative of exploitation attempts targeting CVE-2026-20192 to gain unauthorized administrative access.
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
Detects attempts to disable Windows Defender by either executing known Defender Control utilities or by modifying registry keys associated with the disabling of anti-spyware features or the WinDefend service startup.
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
Detects the clearing of Windows Security Event Logs (EventID 1102) within 15 minutes of a successful user logon (EventID 4624) on the same host. This activity is a common anti-forensics technique used by adversaries to hide malicious actions following an authenticated session.
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
This rule detects attempts to exploit the Microsoft Support Diagnostic Tool (MSDT) vulnerability CVE-2022-30190, known as 'Follina'. The rules monitor for malicious HTTP traffic and payloads that leverage the 'ms-msdt' URI scheme to execute arbitrary commands, often delivered via weaponized documents or external references to remote malicious HTML files.
Detects outbound network traffic exhibiting the default self-signed TLS certificate subject and issuer fields 'O=Cobalt Strike' combined with the known default JA3 fingerprint '72a589da586844d7f0818ce684948eea' associated with Cobalt Strike C2 communication.
Detects DNS queries with abnormally long subdomains matching patterns frequently used by Cobalt Strike DNS Beacons for command-and-control communications. The rule identifies hexadecimal or base32 encoded strings within subdomains that exceed 40 characters in length and occur frequently within a short time window.
Detects network traffic patterns characteristic of the EternalBlue (MS17-010) exploit targeting the SMBv1 protocol. Specifically, it monitors for a malformed SESSION_SETUP request containing an unusually large payload, which is indicative of an attempt to trigger a buffer overflow in the SMB service.
Detects common SQL injection patterns (such as UNION SELECT, tautologies, sleep functions, and information_schema queries) within HTTP URI parameters and HTTP POST request bodies, which are indicative of an attempt to manipulate backend database queries.

