Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,144 detections
Filters
Last updated
All Time
Detection languages
23,200
16,898
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,788
4,478
Categories
20,100
11,460
5,732
4,980
4,798
Platforms
39,725
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,036
15,419
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
KQL Query from file: Detect O365 Activities from OpenAI IP Addresses
Detects suspicious/unexpected usernames appearing in Cisco ISE access.log,
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
Detects the execution of PowerShell scripts containing a combination of Base64 encoding, compression (Deflate/Gzip), and UTF-32 decoding. This specific layering is commonly used to obfuscate malicious payloads and evade signature-based detection mechanisms in PowerShell environments.
Detects multiple endpoints setting their desktop wallpaper to a common file located on a remote UNC path or containing 'sysvol'. This behavior is often indicative of GPO-based configuration for persistence or malware staging, where a malicious 'payload.jpg' is used as a cover or to deliver code via vulnerabilities in image parsing libraries.
Detects modifications to the Windows legal notice registry keys (legalnoticecaption, legalnoticetext) under the System policies registry hive. These keys are used to display a message to users during the login process, and are frequently abused by adversaries for persistence messaging, defacement, or to deliver payloads via social engineering.
This rule detects the execution of LNK or HTA files from a WebDAV share (DavWWWRoot) using common Windows binaries like mshta.exe, wscript.exe, cscript.exe, or explorer.exe. This pattern is commonly associated with the 'ClickFix' technique, where users are lured into opening malicious files hosted on remote WebDAV shares to achieve code execution.
This rule detects PowerShell script blocks containing a suspicious combination of Base64-like character sets and Cyrillic characters. This technique is often used in obfuscated payloads to evade static analysis signatures or to hinder human readability by inserting non-Latin characters within encoded content, which may trigger different parsing behaviors in various environments.
Detects high volumes of HTTP redirect responses (3xx status codes) associated with a single client IP address, which is indicative of a redirect chain often used in malicious activity such as drive-by compromise or social engineering campaigns involving fake browser updates or 'ClickFix' lures.
Detects unauthorized attempts to disable or modify Windows Firewall settings across multiple devices. The rule identifies suspicious registry modifications, firewall service termination events, or security policy changes that suggest an adversary is attempting to impair defensive mechanisms.
Detects the use of legitimate Windows binaries (Rundll32, Wscript, Cscript, and Regsvr32) to execute scripts, HTML applications, or remote scriptlets. This pattern is commonly associated with adversary techniques to proxy execution of malicious code, bypass application controls, or retrieve payloads from remote servers.
Detects the execution of Windows Terminal, PowerShell, or pwsh processes spawned directly by explorer.exe that do not originate from standard Start Menu search or navigation host processes. This pattern is indicative of the user triggering the 'Power User' (Win+X) menu, often associated with adversary attempts to leverage ClickFix-style social engineering lures that rely on the user interacting with specific UI elements.
FileFix lures append a real-looking file path after a '#' comment character so the Explorer address bar visually shows a benign path while the PowerShell prefix executes silently.
Some FileFix/ClickFix chains pivot execution through the mshta.exe living-off-the-land binary immediately after the Explorer address-bar entry, before dropping the final payload.
FileFix's core mechanism abuses the HTML input type=file element; clicking a lure button launches explorer.exe from the browser while JavaScript copies a disguised PowerShell command to the clipboard.
FileFix loader chains abuse trusted code-hosting platforms like Bitbucket/GitHub to host staged payload components, exploiting domain trust to evade network detection.
FileFix lures append a real-looking file path after a '#' comment character so the Explorer address bar visually shows a benign path while the PowerShell prefix executes silently.
Some FileFix/ClickFix chains pivot execution through the mshta.exe living-off-the-land binary immediately after the Explorer address-bar entry, before dropping the final payload.
FileFix's core mechanism abuses the HTML input type=file element; clicking a lure button launches explorer.exe from the browser while JavaScript copies a disguised PowerShell command to the clipboard.
StealC v2, the payload consistently delivered via FileFix campaigns, is capable of stealing cryptocurrency wallet data alongside credentials and VPN configs.
Acronis TRU (Sept 2025) documented a FileFix campaign where a PowerShell loader downloads images from Bitbucket that conceal embedded malicious components, ultimately deploying a Go-based loader and StealC.
The FileFix StealC campaign's final-stage loader is written in Go and performs VM/sandbox checks plus string encryption before executing the infostealer.


