Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
After the initial FileFix paste-and-execute step, observed campaigns chain into a secondary download of the real payload using LOLBins or PowerShell web clients.
Acronis reported a multilingual FileFix phishing site using anti-analysis techniques and advanced obfuscation, chaining into a Go-based loader with string encryption before deploying StealC.
This rule detects a behavioral chain characteristic of the KongTuke/LandUpdate808 threat actor group. It identifies the correlation between a browser initiating a network connection to a domain with a low-reputation top-level domain (TLD) and that same browser process launching 'explorer.exe' within a 60-second window. This behavior is associated with social engineering lures (fake CAPTCHA) that encourage users to execute clipboard commands, which trigger file-picker dialogs via explorer.exe to facilitate follow-on malicious activity.
FileFix JavaScript silently writes the malicious command to the clipboard the instant the lure button is clicked, producing a much shorter human-reaction interval between browser launch and shell spawn than a manually typed path would allow.
A July 2026 incident used Polygon smart contracts (EtherHiding) for dynamic payload routing/C2 following a ClickFix/FileFix-style lure driven by compromised WordPress credentials.
Detects the creation of registry keys associated with the installation of Chrome or Edge browser extensions, specifically targeting the behavior exhibited by the CrashFix malware which masquerades as an ad blocker to achieve persistence.
Detects anomalous Telnet (TCP port 23) traffic associated with Mirai-variant botnet propagation, such as scanning for new targets or inbound compromise attempts, often following cPanel/WHM vulnerabilities.
This rule detects high-confidence phishing emails that were delivered to either the Inbox or Junk folder. It explicitly filters out messages that have been explicitly allowed by organization-level policies, user-level actions, or specific safe-sender bypass mechanisms, ensuring the alert focuses on malicious emails that bypassed standard security filters without an authorized exception.
This rule detects high-confidence phishing emails that were delivered to either the Inbox or Junk folder. It explicitly filters out messages that have been explicitly allowed by organization-level policies, user-level actions, or specific safe-sender bypass mechanisms, ensuring the alert focuses on malicious emails that bypassed standard security filters without an authorized exception.
Detects potential abuse of stolen OAuth session tokens, where refresh tokens are used to authenticate after a user has performed a password reset. This rule identifies accounts that continue to sign in from previously unseen devices or IP addresses within 24 hours post-password reset, a technique consistent with session persistence mechanisms used by adversary tools and platforms like EvilTokens.
This rule detects scenarios where a user completes a device-code authentication flow, followed immediately (within 10 minutes) by the registration of an unmanaged, non-compliant device to their account. This behavior is indicative of potential token theft (e.g., EvilTokens) where an adversary uses a stolen token to register their own device as a persistent, unmanaged entity, bypassing standard corporate device enrollment controls.
Detects the creation of an email inbox rule that includes both a concealment/deletion action and an external forwarding destination, occurring within 4 hours of a high-risk or compromised device-code authentication event. This pattern is indicative of account takeover where an attacker establishes persistence and exfiltration while hiding their activity.
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
Detects reconnaissance and lateral movement activity via kubectl. The rule monitors for the enumeration of Kubernetes secrets or configmaps, and the deployment or application of privileged workloads featuring flags such as hostPath mounts, privileged execution, hostNetwork, or hostPID.
Detects HTTP and TLS activity associated with the DSCourier malware, specifically identifying attempts to retrieve configuration files disguised as common non-executable extensions (.jpg, .txt) or utilizing non-standard network ports like 8443, which are characteristic of this threat's command and control behavior.
Detects the use of 'winget configure' to retrieve and apply a Desired State Configuration (DSC) file from a remote HTTPS URL. This behavior can be abused to execute malicious configuration scripts directly from the internet.
Detects the creation of a 'SystemIn.lnk' persistence shortcut on Windows systems using PowerShell and the WScript.Shell COM object. This activity is associated with the QUICAgent backdoor, part of the QUICSILVER operation, which uses temporary PowerShell scripts to establish persistence.
Detects the execution of AutoIt3.exe or AutoIt-related scripts (.a3x, .au3) spawned by mshta.exe. MSHTA is a legitimate utility that can be abused to proxy the execution of malicious code, and in this context, it may be used to launch AutoIt scripts to evade security controls or execute payloads.
Detects memory allocation (VirtualAlloc/AllocateVirtualMemory) or protection (VirtualProtect/ProtectVirtualMemory) API calls performed with 'EXECUTE_READWRITE' permissions where the call stack is missing, unbacked, or contains unknown modules. This behavior is highly indicative of code injection techniques where an adversary attempts to execute shellcode or reflectively load a payload into memory while attempting to hide the origin of the execution.


