Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the creation of a scheduled task using schtasks.exe that involves 'keyroll' in the command line. This pattern specifically flags tasks associated with the 'rnpkeys.exe' utility or tasks being created within 'keyroll' directories, which may indicate the deployment or maintenance of unauthorized key management or persistence mechanisms.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
Detects the modification of the 'DisableRestrictedAdmin' registry key via 'reg.exe'. This registry setting, when disabled (set to 0), allows the use of 'Restricted Admin' mode for Remote Desktop connections, which can be leveraged to bypass certain credential protections or enable lateral movement using high-privilege credentials.
Detects the 'mscopilot.exe' binary performing token manipulation operations (DuplicateTokenEx, ImpersonateLoggedOnUser, SetThreadToken) followed by the creation of a new process with a different security context (CreateProcessAsUserW) within a five-minute window, indicative of C2 agent functionality.
Detects anomalous lateral movement behavior where a user account authenticates via NTLM (Logon Type 3) to at least three different hosts within a 10-minute window and subsequently accesses administrative network shares (ADMIN$ or C$) on one or more of those target systems.
Detects the creation of web scripts (aspx, php, jsp) in typical web server directories followed by suspicious shell activity (cmd, powershell, or shell execution) originating from web server processes within a 10-minute window. This behavior is indicative of a web shell being dropped and subsequently utilized for command execution.
Detects potential exploitation attempts of the Zerologon vulnerability (CVE-2020-1472) by monitoring for Domain Controller machine account password resets (Event 4742) targeting DC computer accounts, and insecure Netlogon RPC channel events (Event 5829) triggered when vulnerable clients or tools attempt connections.
Detects the Print Spooler service (spoolsv.exe) spawning a shell/script interpreter or rundll32.exe as a child process, or loading a DLL from a driver-store/temp/ProgramData path — the process-injection and arbitrary-DLL-load pattern characteristic of PrintNightmare (CVE-2021-34527) exploitation.
Detects the WMI provider host process (WmiPrvSE.exe) spawning common command-line or system administration tools such as cmd.exe, powershell.exe, or rundll32.exe. This activity is correlated with a preceding network connection to the host on port 135 (DCOM/WMI), which is indicative of lateral movement using WMI.
This rule detects potential Golden Ticket activity by identifying Kerberos TGS requests (Event ID 4769) that lack a corresponding prior TGT request (Event ID 4768) for the same user and IP address. This behavior is characteristic of offline forged Kerberos tickets where an attacker uses a compromised KRBTGT hash to create authentication tickets without interacting with the Key Distribution Center for the initial TGT.
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
Detects NTLM network logons (LogonType 3 or 9) which often result from a host resolving an attacker-supplied UNC path (e.g., \host
esource) during forced authentication attacks. This rule monitors Windows Security Event ID 4624 to identify incoming NTLM-based network authentication requests, excluding local system logons.
Detects modifications to the Windows Subsystem for Linux (WSL) InstallLocation registry key.
Attackers can modify this registry key to redirect the execution flow of legitimate WSL processes (wsl.exe or bash.exe) to a malicious payload, acting as a proxy execution and defense evasion technique.
Attackers can modify this registry key to redirect the execution flow of legitimate WSL processes (wsl.exe or bash.exe) to a malicious payload, acting as a proxy execution and defense evasion technique.
This rule identifies installations of TeamViewer software that are vulnerable to specific CVEs (CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371) by analyzing the 'DeviceTvmSoftwareInventory' dataset. It checks for versioning patterns against known vulnerable build numbers across Windows, Linux, and macOS platforms to pinpoint systems requiring patching.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Page 25 of 1866



