Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects common SQL injection patterns (such as UNION SELECT, tautologies, sleep functions, and information_schema queries) within HTTP URI parameters and HTTP POST request bodies, which are indicative of an attempt to manipulate backend database queries.
Detects HTTP POST requests with 'photo' in the URI and Gzip-compressed body content, which is a known C2 communication pattern used by the IcedID banking trojan.
Detects high-volume SSH authentication attempts originating from a single source IP targeting a server on port 22, indicating a potential brute force attack.
Detects HTTP POST requests characteristic of TrickBot C2 beaconing. The rule identifies specific URI structures, Content-Type headers set to 'application/octet-stream', and unique request body behaviors that are indicative of TrickBot communication patterns.
Detects HTTP traffic patterns characteristic of Qakbot (QBot) malware command-and-control (C2) communication. This rule monitors for POST requests to .php files featuring a specific hardcoded User-Agent (IE 7.0 on Windows NT 5.1), a 'Cookie' header, 'application/octet-stream' content type, and a request body length of at least 201 characters.
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
Detects HTTP traffic patterns associated with the default staging URIs of the PowerShell Empire C2 framework. This rule identifies inbound requests to specific .php files (admin/get, news, login/process) with a 'session=' cookie, which are characteristic of Empire agent beaconing behavior.
This rule monitors for known string patterns associated with the initialization and command execution of the Metasploit Meterpreter reverse TCP payload. By inspecting network traffic for characteristic C2 handshake and command strings, it identifies active Meterpreter sessions.
Detects DNS tunneling attempts by identifying DNS queries with abnormally long subdomains (greater than 50 characters) that exhibit a high request rate (20 or more queries within 60 seconds). This behavior is characteristic of C2 communication tools such as iodine or dnscat2, which encode data within DNS query labels to bypass traditional network security controls.
Detects sequential suspicious SMB activity characteristic of PsExec lateral movement: connection to ADMIN$ or C$ administrative shares, followed by the upload of an executable or batch file to the share, and subsequently the usage of SVCCTL (CreateServiceW/StartServiceW) to execute the uploaded binary.
Detects a suspicious volume of cloud resource deletions occurring within a short 15-minute window, specifically targeting multiple storage accounts and SQL database/server instances. This behavior is indicative of a malicious actor or an automated script attempting to disrupt business operations or destroy data.
Detects instances where a user account registers a new Multi-Factor Authentication (MFA) method (such as TOTP or Authenticator app) shortly (within 30 minutes) after a high-risk or potentially anomalous sign-in event. This pattern is commonly associated with adversary-in-the-middle (AiTM) phishing attacks where an attacker captures an authenticated session and uses it to enroll a secondary, attacker-controlled MFA device for persistent account access.
The following analytic identifies when an O365 email recipient receives and then deletes emails related to password or banking/payroll changes within a short period.
This behavior may indicate a compromised account where the threat actor is attempting to redirect the victims payroll to an attacker controlled bank account.
This behavior may indicate a compromised account where the threat actor is attempting to redirect the victims payroll to an attacker controlled bank account.
The following analytic identifies when an O365 email account sends an excessive number of email attachments to external recipients within a short period (within 1 hour).
This behavior may indicate a compromised account where the threat actor is attempting to exfiltrate data from the mailbox.
Threat actors may attempt to transfer data through email as a simple means of exfiltration from the compromised mailbox.
Some account owner legitimate behaviors can trigger this alert, however these actions may not be aligned with organizational expectations / best practice behaviors.
This behavior may indicate a compromised account where the threat actor is attempting to exfiltrate data from the mailbox.
Threat actors may attempt to transfer data through email as a simple means of exfiltration from the compromised mailbox.
Some account owner legitimate behaviors can trigger this alert, however these actions may not be aligned with organizational expectations / best practice behaviors.
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
Detects an Active Directory Certificate Services (AD CS) Certificate Enrollment Service (CES) SOAP request that includes a 'CertificateTemplate' item in the 'AdditionalContext' body, potentially indicating a directed attempt to request a specific certificate template during enrollment.
This rule detects potential NTLM relay or authentication downgrade attempts by monitoring HTTP POST requests to the Certificate Enrollment Service (CES) endpoint. It specifically flags when an 'Authorization' header contains an NTLM-wrapped 'Negotiate' token, which is often indicative of an attacker attempting to coerce or relay authentication material to the service.
The following analytic identifies instances where CrushFTP has blocked access due to exceeding the maximum number of simultaneous connections from a single IP address. This activity may indicate brute force attempts, credential stuffing, or automated attacks against the CrushFTP server. This detection is particularly relevant following the discovery of CVE-2025-31161, an authentication bypass vulnerability in CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.
The following analytic detects Log4Shell JNDI payload injections via outbound connections. It identifies suspicious LDAP lookup functions in web logs, such as `${jndi:ldap://PAYLOAD_INJECTED}`, and correlates them with network traffic to known malicious IP addresses. This detection leverages the Web and Network_Traffic data models in Splunk. Monitoring this activity is crucial as it targets vulnerabilities in Java web applications using log4j, potentially leading to remote code execution. If confirmed malicious, attackers could gain unauthorized access, execute arbitrary code, and compromise sensitive data within the affected environment.
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.

