Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Movie Reaper Activity
YARA-L
Detects activity associated with MovieReaper campaign including process, file, and network indicators
Detects the execution of rundll32.exe where the command line points to a DLL file located on a remote WebDAV share (using the 'davwwwroot' path syntax). This technique is often used to execute malicious payloads while bypassing local disk protections.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects the installation of a new kernel-mode service using system utilities like sc.exe, cmd.exe, or powershell.exe, which is a common indicator of a Bring Your Own Vulnerable Driver (BYOVD) attack intended to gain kernel-level privileges.
Detects the execution of known NetSupport Manager remote access tool binaries from locations outside of the official installation directories. This behavior is indicative of unauthorized use or persistence of remote management software, often used as a RAT by adversaries.
Detects unusual network connections over port 445 involving SMB named pipes commonly associated with lateral movement tools or P2P beaconing. The rule identifies communication through suspicious or generic pipe naming conventions that deviate from standard system process behavior (e.g., lsass, services, svchost, System).
Detects the loading of amsi.dll by common .NET loader processes, which may indicate attempts to patch or bypass the Antimalware Scan Interface (AMSI) in memory. The rule monitors for image load events of amsi.dll and correlates them with process creation events of known loaders such as powershell.exe, rundll32.exe, and others.
Detects processes attempting to load ntdll.dll or utilizing DLLs in a manner that may indicate the use of indirect syscalls, a technique used by malware to bypass EDR/AV user-mode API hooking.
This rule detects potential PIVOTPIPE activity by correlating AMSI patching indicators with anomalous memory protection changes. It identifies processes that perform frequent transitions to PAGE_EXECUTE_READWRITE or PAGE_NOACCESS, which is indicative of memory-based obfuscation techniques used to evade memory scanning and detection during sleep cycles.
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
Page 245 of 1871

