Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
This rule detects network traffic containing the specific 'Xwormmm' string in the payload, which serves as a handshake or banner characteristic of XWorm command-and-control (C2) communications.
Detects incoming TLS traffic from an external network where the TLS server certificate's Subject Common Name (CN) field matches 'AsyncRAT Server'. This pattern is a known indicator of a beaconing session initiated by AsyncRAT remote access trojan servers.
This rule detects network traffic patterns associated with the Lumma Stealer malware performing endpoint fingerprinting. It monitors for GET requests to the URI path '/api/set_agent' which contains a 32-character hexadecimal string, characteristic of the malware's C2 communication.
This rule detects network traffic indicative of the RisePro malware communicating with its Command and Control (C2) infrastructure. It specifically looks for the 'clientsendfile' string within the payload, which acts as a keepalive signal or heartbeat for the RisePro implant.
Detects network traffic associated with the RisePro malware family, specifically identifying the use of 'serversendfile' commands, which indicates data exfiltration or file transfer activity via a command-and-control channel.
This rule detects outgoing HTTP POST requests to discord.com API webhooks, specifically containing patterns characteristic of XWorm malware, such as exfiltrating machine information identified by Username and IP fields.
This rule detects potential command-and-control (C2) communication associated with the Pikabot malware. The detection looks for outbound HTTP POST requests to external networks that lack a 'Content-Type' header and contain a non-empty, specifically sized request body, which are behavioral indicators consistent with Pikabot beaconing activity.
Detects outbound HTTP POST requests to known blockchain RPC endpoints (bsc-dataseed and rpc.ankr.com) that utilize the 'eth_call' method. This behavior is associated with the ClearFake malware strain using the EtherHiding technique, where malicious scripts or payloads are hidden or retrieved via blockchain smart contracts.
This rule monitors HTTP traffic for requests containing 'bp.dat', which is associated with the registration phase of the Latrodectus malware downloader. It detects both URI-based and request body-based attempts by an infected host to register with a command and control server.
Detects outbound network traffic containing the hardcoded user-agent string 'Remcos', which is indicative of a Remcos RAT beacon communicating with a command-and-control (C2) server. The rule inspects HTTP requests to identify this specific malware signature within the established communication flow.
Detects HTTP GET requests originating from internal hosts to external destinations where the User-Agent string contains 'AutoIt'. This behavior is indicative of the DarkGate malware downloading additional payloads or components using AutoIt scripting capabilities.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
Detects the installation of a specific known malicious npm package named 'tw-pkgprobe-7731' via the command line, which may indicate a supply chain compromise or an attempt to execute malicious code within a development environment.
Detects Node.js processes establishing network connections to common webhook relay and collection services, which may indicate data exfiltration or credential theft.
Detects DNS queries for the domain 'pdf.gusercontent.com', which is known to be used as a lookalike domain for Google-related services to deceive users. This pattern is often indicative of malicious infrastructure used for credential harvesting, phishing, or malware delivery.
Detects unauthorized outbound network traffic from browser processes to the lookalike domain 'pdf.gusercontent.com'. This domain is associated with a malicious Firefox browser extension, 'PDF Identity Verifier', which is designed to exfiltrate session telemetry and data from Google account sessions.
Detects requests to the FedCM (Federated Credential Management) well-known configuration endpoint (.well-known/web-identity) that originate from referrers containing 'gusercontent.com', often used in phishing or credential harvesting campaigns to simulate legitimate Google authentication flows.
This rule detects PowerShell commands that attempt to reassemble a Base64-encoded payload from multiple concatenated variable fragments. It specifically looks for patterns where filler characters ('*' or '?') are stripped from the payload before it is passed to the [Convert]::FromBase64String method. This technique is commonly used to evade static string analysis and signature-based detection.
Detects the Windows Character Map utility (charmap.exe) loading suspicious modules such as amsi.dll or clr.dll followed by a process execution involving PowerShell or an unidentified command string, which is indicative of DLL side-loading or process hollowing techniques for malicious code execution.
Detects the execution of PowerShell with encoded commands that explicitly perform base64 string decoding using 'FromBase64String'. This pattern is frequently used to obfuscate scripts or payloads, often seen in downloader stagers or malicious scripts to bypass security controls.


