Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,144 detections
Filters
Last updated
All Time
Detection languages
23,200
16,898
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,788
4,478
Categories
20,100
11,460
5,732
4,980
4,798
Platforms
39,725
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,036
15,419
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a specific behavioral chain associated with the CHOSEN BRICK implant. This rule identifies when a suspected malicious process writes image/screenshot files (.png, .jpg, .bmp) to disk, followed by a network connection to the Telegram Bot API within a 15-minute window, suggesting potential data exfiltration.
This rule detects potential persistence via Python environment variable manipulation (PYTHONPATH) followed by suspicious network activity from a child process of python.exe. It specifically looks for the modification of the PYTHONPATH environment variable using PowerShell on Windows or shell configuration files on Unix-like systems, followed by a python.exe-initiated network connection (like curl) to external domains, which may indicate the execution of a malicious sitecustomize.py hook.
Detects the use of Python or Pip utilities as parent processes to spawn potentially malicious binaries such as cmd.exe, powershell.exe, curl.exe, or rundll32.exe. This activity is often associated with the execution of downloaded payloads or shell commands directly through package manager workflows.
Detects process execution attempts where the binary is located in specific, non-standard macOS system library paths often associated with background tasks or masquerading, specifically when the process is invoked with a '--type=renderer' command-line argument. This is a common pattern for malicious code attempting to mimic browser-based or helper processes.
This rule detects instances where Python package management processes (pip or python) perform build or installation tasks, immediately followed by an outbound network connection initiated by the same process tree to a non-PyPI domain. This behavior is indicative of a supply chain attack where a malicious package contains code (e.g., in setup.py) that beacons to an attacker-controlled server upon installation.
This rule detects the creation, modification, or renaming of files within specific sensitive directories under Local AppData (such as ComponentTask33, INetCache/FilterManager, or Shell/RemoteTempPrimary) that are closely timed with the execution of a PowerShell script named '*_scatter.ps1'. This behavior is indicative of potential malicious staging, data dropping, or modular deployment associated with a specific script-based attack chain.
This rule detects suspicious process lineage where a Python interpreter executes system commands indicative of a compromised or trojanized pandas package. Specifically, it identifies Python processes spawning command-line utilities for malicious shell operations (e.g., cmd.exe /c calc.exe on Windows or uname -a on Linux/macOS), suggesting an attempt to verify successful arbitrary code execution via a hijacked library function like read_json.
This rule detects suspicious process lineage where Python (python.exe or pip.exe) is initiating the execution of Windows command shell (cmd.exe) or Windows calculator (calc.exe). This pattern is often associated with exploitation of malicious Python site-hook files or similar techniques where a Python environment is leveraged to spawn secondary processes, potentially leading to unauthorized command execution.
This rule detects potentially malicious command execution patterns where a Python interpreter (python.exe) is invoked with the '-m' flag to execute a module, which subsequently spawns a command shell (cmd.exe) as a child process. This behavior is often associated with adversary attempts to leverage Python's capabilities for system interaction, payload execution, or lateral movement, as documented in various campaigns that abuse Python as a living-off-the-land binary.
Identify cases where privileged tokens appear in unexpected contexts (e.g., admin accounts logging into low-tier devices, unusual logon types, or rare hosts).
Detects bulk file access or modifications involving sensitive files such as certificates (.pfx, .p12, .pem, .key), password manager vaults (.kdbx, .kdb), and files containing keywords related to credentials or logins. This behavior is indicative of an adversary staging or exfiltrating sensitive security material for further credential access.
Detects the SharePoint application pool worker process (w3wp.exe) spawning command-line interpreters or scripting engines. This behavior is indicative of post-exploitation activity where an attacker, having gained remote code execution via techniques like insecure deserialization, executes commands or deploys in-memory webshells within the context of the IIS worker process.
Detects unauthorized attempts to access SharePoint's WebPartPage ToolPane and Gallery endpoints via anonymous web requests. This pattern, characterized by the 'DisplayMode=Design' query parameter and suspicious markup in the request body, is indicative of exploitation attempts targeting vulnerable SharePoint installations to execute arbitrary code or bypass authentication mechanisms.
This rule detects potential persistence mechanisms by monitoring for the creation of scheduled tasks using the 'OneDriveUpdateScheduler' name, as well as the execution of suspicious scripts named 'update1.vbs' or 'update1.ps1' by wscript.exe, cscript.exe, or powershell.exe when spawned from explorer.exe.
Detects HTTP traffic patterns associated with the VelvetCake malware used by North Korean threat actors Konni and Kimsuky. These signatures identify beaconing behavior to known free-hosting infrastructure, specifically monitoring for unique URL parameters ('OKey=', 'Who=', 'Areyou=cake') and common file naming conventions associated with the C2 communication.
Detects VBScript files that exhibit characteristics of a downloader or dropper, including common Windows API usage (WScript.Shell, Shell.Application, MSXML2.XMLHTTP, ADODB.Stream), staging in the C:\Users\Public\ directory, and performing sandbox evasion via WMI InstallDate checks.
This rule detects potential dropper activity associated with the TrustSink/XHOPLESS threat actor, specifically involving an 'Evernote.zip' file staged in the C:\Users\Public directory. It monitors for the automated extraction of files (like a repurposed notepad++.exe) using VBScript's Shell.Application or WScript.Shell, which is indicative of a side-loading attack chain.
Detects an attempt to bypass SharePoint authentication using a 'Register' directive in a POST request body directed at an .aspx page that is not a recognized ToolPane page. This pattern is indicative of an exploit attempt against a public-facing SharePoint server, specifically targeting vulnerability CVE-2026-65660.
Detects anomalous child process execution from SharePoint's w3wp.exe worker process following the loading of suspicious .NET assemblies (PresentationFramework.dll, System.Xaml.dll, System.Data.Services.dll). This behavior is indicative of a post-exploitation stage for SharePoint SafeControls bypass vulnerabilities, where a gadget chain is utilized to execute unmanaged or child processes.
Detects rapid, automated-style creation of an application, associated service principal, and delegated permission grants within a 60-second window. This behavior is indicative of the TrustSink technique or similar automated adversary infrastructure setup in Microsoft Entra ID (formerly Azure AD), where an attacker establishes persistence or elevated access through newly created apps.
This rule monitors inbound emails for sender domains or embedded URLs that contain strings related to popular AI service brands (e.g., ChatGPT, Gemini, Claude). It flags these occurrences when the domain does not match the official, legitimate domains for those services, indicating potential phishing or brand impersonation attempts.



