Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects web proxy requests that resemble phishing attempts targeting Apple Activation Lock. The rule identifies URLs containing specific Apple-related keywords in combination with common phishing URL paths, while filtering out legitimate Apple support documentation pages.
Detects the presence of the i-Realm companion tool associated with the AnonyMousKIT PhaaS platform, which is designed to bypass iOS Activation Lock features.
Detects a sequence of suspicious identity activities indicative of a post-account-takeover pivot. The rule identifies a user profile engaging in corporate VPN SAML SSO probing, triggering a MFA enrollment interrupt in Azure, and subsequently accessing multiple Microsoft 365 applications (Azure Portal, OfficeHome, SharePoint) within a 30-minute window.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
This rule detects suspicious activity associated with Redis server processes attempting to write to SSH 'authorized_keys' files or executing commands (such as BGREWRITEAOF or directory reconfiguration) commonly used by attackers to inject malicious SSH public keys into a Redis installation for persistent remote access.
Detects a multi-stage attack chain involving the download, extraction, permission modification, and execution of the XMRig cryptocurrency miner on Linux systems. The rule specifically monitors for common staging patterns in /tmp and the use of known mining-related CLI arguments.
Detects the creation or modification of a file within the /etc/cron.d/ directory, followed shortly by a Bash process invocation using /dev/tcp redirection. This pattern is commonly used by attackers to achieve persistence via cron and establish reverse shells, bypassing potential limitations of default system shells that do not support /dev/tcp syntax.
Detects a post-compromise pattern on a WordPress site where an attacker, after an initial login, rapidly accesses multiple sensitive administrative pages (plugins.php, profile.php, etc.) within a short window, suggesting nonce harvesting. This activity is correlated with the subsequent creation of a suspected webshell file named 's.php'.
Detects network traffic consistent with the XMRig cryptocurrency mining tool communicating with a Monero mining pool via TLS. The rule identifies specific SNI domains and direct connection attempts to known proxy IP addresses associated with cryptomining activities.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
Detects anomalous external traffic patterns indicative of automated API reconnaissance. The rule flags high-frequency requests from a single IP targeting a diverse set of API endpoints, particularly when characterized by a mixture of successful (200), unauthorized (403), or not found (404) status codes, or repeated attempts to access sensitive management/administrative API paths.
Detects a sequence of activity indicative of beacon-like behavior: initial domain reconnaissance using commands such as 'net', 'systeminfo', or 'nltest', followed by the execution of 'rundll32.exe' without command-line arguments, and subsequent LDAP (port 389) communication to a domain controller, all occurring within a short timeframe.
Detects instances where browser processes (Chrome or Edge) are spawned by smartscreen.exe and subsequently access sensitive browser storage files such as Login Data, Cookies, or Local State. This pattern is indicative of a process injection or masquerading chain used to extract credentials or session data.
Detects potential lateral movement or pivot attempts by correlating repeated failed RDP logons (RemoteInteractive) against sensitive targets (Domain Controllers, File Servers, Backup Servers) with concurrent security tool blocks (e.g., Microsoft Defender Antivirus, Exploit Guard) on the originating beachhead device within a 4-hour window.
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
This rule detects potentially malicious process execution chains where VBScript or unknown/suspicious binaries (such as ProfileQuickHost.exe) are used to launch Node.js processes, specifically targeting JavaScript files or VBScript agents. This pattern is often associated with the execution of remote access trojans (RATs) or custom malware loaders.
Detects high-volume credential brute-forcing activity targeting Dahua IP camera administrative interfaces (Ports 80/37777). The rule identifies a pattern of multiple connection failures across multiple distinct targets followed by a successful connection, which is highly characteristic of automated credential stuffing or password spraying attacks against embedded IoT devices.



