Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where PowerShell processes initiate outbound WebDAV connections, potentially to download or stage malicious DLLs. The detection rule correlates network activity involving WebDAV indicators (e.g., DavWWWRoot) with subsequent local file creation events for DLL files within WebDAV-related folders.
Flags anomalous volume of Entra ID sign-ins using the device-code authorization grant, matching the Kali365 phishing-as-a-service technique (sold on Telegram, ~$250/month per FBI PSA) that captures Microsoft 365 OAuth tokens through the legitimate device-code flow.
Detects tenant-level enablement of Microsoft Teams external/federated access or addition of an unfamiliar external domain shortly before a spike in inbound Teams calls to helpdesk/IT-support-tagged users — models CrowdStrike's 2026 Financial Services Threat Landscape Report on 'Mutant Spider,' the most active threat to financial services, whose primary technique is voice phishing over Microsoft Teams impersonating internal IT.
Flags installation of RMM tools (AnyDesk, ScreenConnect, TeamViewer, Atera, Splashtop) on an endpoint shortly after that user's account undergoes a password/MFA reset — matches the post-vishing tooling pattern CrowdStrike attributes to Mutant Spider (loaders including PrionFlaire and SocksLoader) and Scattered Spider.
Detects a suspicious sequence of identity-related operations performed by a single user within a 2-hour window. The chain consists of a password reset, MFA method modification, new device registration, and a subsequent privilege escalation event (such as role assignment or application consent). This pattern is consistent with helpdesk-vishing campaigns often used by threat actors like Scattered Spider to perform full account takeovers.
Detects instances where WScript or CScript (Windows Script Host) spawns PowerShell with common obfuscation and persistence flags, specifically executing in a hidden, non-interactive, headless, and encoded command mode. This pattern is commonly used by malicious scripts (e.g., VBScript or JScript) to execute secondary payloads while minimizing visual indicators on the host.
Detects the spawning of suspicious child processes (powershell, cmd, node, wscript, cscript) by dependency management utilities (npm, go, terraform). Attackers often leverage malicious packages or configurations during the build or install phase to execute arbitrary code. The rule also monitors for suspicious command-line execution patterns, such as detached 'go run' operations, which may indicate malicious activity.
Detects instances where the Terraform process initiates a 'go run' command or references specific Go-based provider source files, which may indicate an attempt to run malicious or unauthorized Go code within the infrastructure-as-code environment. This behavior is indicative of supply chain compromise where providers are leveraged to execute arbitrary logic.
Detects the creation of a new local user account named 'ops' or an account with 'full' group privileges on MikroTik RouterOS. This rule is designed to identify potential persistence mechanisms following the exploitation of MikroTrick vulnerabilities (CVE-2026-67279/CVE-2026-86060), often indicated by anomalous prior login patterns.
Detects unauthorized export and outbound exfiltration of MikroTik RouterOS .rif diagnostic files. These files contain sensitive device configuration data and are often targeted during the final stage of the 'MikroTrick' attack chain, following administrative credential compromise.
Detects attempts to perform path traversal attacks against the MikroTik RouterOS WebFig interface via the jsproxy endpoint. The rule monitors HTTP proxy traffic for directory traversal sequences (e.g., '../' or URL encoded equivalents) within the query parameters of requests directed to the jsproxy URI.
Detects instances where explorer.exe (the Windows Shell) spawns a PowerShell process with suspicious flags, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands into the Windows Run dialog.
Detects the Graphalgo Go-based remote access trojan (RAT) sending an initial system report containing device and user information to the Slack API. This activity occurs during the initial check-in phase before establishing a primary command and control channel.
Detects critical log entries on MikroTik RouterOS devices that contain 'flagged' status messages following a system upgrade or maintenance. This pattern is indicative of potential post-exploitation activity or post-update integrity warnings identified in recent vulnerabilities affecting RouterOS.
Detects high-risk destructive database operations (DROP, TRUNCATE, or UPDATE) on sensitive tables executed within six hours of a large outbound data transfer from the same host, a pattern indicative of anti-forensic database wiping following data exfiltration.
Detects the 'ClickFix' technique where a user is socially engineered into copying a malicious command to their clipboard and pasting it into the Windows Run dialog (Win+R). The rule monitors for powershell.exe spawned by explorer.exe containing specific social engineering keywords or typical fileless download-execute patterns like 'irm', 'iex', or 'Invoke-RestMethod'.
KQL Query from file: TerminalFix Detection
This rule detects the suspicious use of signed Windows binaries (rundll32.exe, regsvr32.exe, mshta.exe, msiexec.exe) to execute remote content via URLs or scripts, or when triggered by common office applications and browsers. This behavior is often indicative of living-off-the-land (LotL) techniques used for download/execution of payloads or bypassing security controls.
This rule detects potential Pass-the-Hash lateral movement by identifying NTLM network logons (Event ID 4624, LogonType 3) on a host that lack a preceding interactive (LogonType 2, 10) or Kerberos-authenticated logon, coupled with subsequent access to sensitive administrative shares (Event ID 5140) by the same user account.
Detects the execution of PowerShell with suspicious command-line patterns indicative of obfuscation or malicious intent, including encoded commands, Base64 decoding, IEX combined with common download cmdlets, and specific obfuscation techniques like backtick concatenation, character casting, or variable concatenation.
Detects anomalous Kerberos ticket requests that are characteristic of Golden Ticket attacks. The rule flags the use of weak encryption types (e.g., RC4) commonly used in forged tickets even in AES-enforced environments, and direct requests for the KRBTGT service account outside of legitimate ticket renewal operations.

