Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects modifications to the Chrome browser's registry key that stores extension settings. Adversaries may modify these registry keys to silently install, enable, or configure malicious browser extensions for persistence and credential theft.
Detects the creation of a new Windows service using the service control manager command-line utility (sc.exe). This command is commonly used by attackers to achieve persistence by creating services that execute malicious binaries at startup, or to run processes with SYSTEM privileges.
This rule detects the execution of the legacy finger.exe utility when spawned by common user-facing applications (e.g., browsers, shells, explorer). The detection specifically looks for instances where the command line includes an '@' character, indicating an attempt to query information from a remote host, while excluding standard localhost queries. This pattern is often associated with reconnaissance activity or enumeration of remote users/systems.
This rule detects the execution of the legacy finger.exe utility when spawned by common user-facing applications (e.g., browsers, shells, explorer). The detection specifically looks for instances where the command line includes an '@' character, indicating an attempt to query information from a remote host, while excluding standard localhost queries. This pattern is often associated with reconnaissance activity or enumeration of remote users/systems.
Detects the execution of IronPython or generic Python interpreters where the command line contains suspicious obfuscation patterns, including base64-encoded strings, zlib compression/decompression, and the use of the subprocess module. This pattern is commonly used by adversaries to execute hidden or obfuscated malicious payloads.
Detects DNS resolutions for Microsoft Graph API endpoints (graph.microsoft.com) initiated by processes other than standard, expected Microsoft applications (e.g., Outlook, Teams, OneDrive). This behavior may indicate unauthorized processes or potential beaconing/C2 activity masquerading as legitimate Microsoft cloud service traffic.
Detects two distinct methods used for persistence and execution: 1) Addition of 'rundll32' to Windows Registry Run keys, often used to execute malicious code upon logon. 2) Creation or modification of COM InprocServer32 registry keys, a technique known as COM Hijacking used to load malicious DLLs when a legitimate COM object is initialized.
Detects the invocation of common command-line interpreters (PowerShell or Windows Command Shell) via process creation events. This is a broad detection for administrative shell activity, which may also indicate malicious script execution or manual adversary interaction.
Detects the loading of the kernel driver 'Alinubx.sys', identified as a renamed instance of the 'CcProtect.sys' driver. This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, specifically observed in the context of Rapuncel infostealer campaigns.
Detects outbound network activity on TCP port 79 (finger) initiated by a client to the domain 'finger.linked4x.com'. This behavior is associated with the SloppyRAT 'ClickFix' campaign, where attackers use social engineering to trick users into executing commands, leading to payload staging and tool retrieval.
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
Detects the execution of 'bun' during a Node.js package installation process (npm or node). This behavior can be indicative of a supply chain attack where malicious actors attempt to leverage alternative runtimes during the 'preinstall' phase or package installation to execute arbitrary code or bypass security controls typically associated with standard Node.js installations.
Detects the execution of PowerShell with encoded commands or Base64 decoding attempts initiated by common Windows shell applications (explorer, mshta, wscript, cscript) launched from an LNK file. This pattern is commonly associated with malicious LNK shortcuts used as initial access vectors or stage-two downloaders.
This rule detects potential lateral movement by monitoring successful network logons using NTLM authentication across multiple distinct destination hosts within a short time window. It calculates the frequency of connections to unique hosts to identify anomalous, rapid traversal through a network by a single user account, excluding known system accounts.
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
Detects malformed HEIF/HEIC image files with anomalous ftyp/box structure consistent with the libheif memory corruption exploit (CVE-2026-32882) used against Discourse forum image upload endpoints
This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
Page 242 of 1871


