Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where a non-administrative user grants an OAuth application consent to access high-privilege Microsoft Graph scopes, such as 'Mail.Read', 'Directory.ReadWrite.All', or 'offline_access'. This pattern is frequently used in consent phishing attacks to maintain persistent access to sensitive cloud resources.
Detects anomalous lateral movement behavior where a single user account authenticates via NTLM to three or more distinct target hosts within a short time window (10 minutes). This pattern of rapid, broad authentication is a strong indicator of a Pass-the-Hash (PtH) attack.
Detects unauthorized directory service access requests (Event ID 4662) utilizing the 'DS-Replication-Get-Changes' or 'DS-Replication-Get-Changes-All' extended rights GUIDs. These rights are required for the DCSync technique used by tools like Mimikatz or Impacket to replicate Active Directory data. The rule specifically flags when such requests originate from a non-domain controller host, which is a strong indicator of credential theft or unauthorized replication attempts.
This rule detects potential lateral movement via WMI by identifying two distinct suspicious behaviors: WmiPrvSE.exe spawning unexpected child processes (excluding common legitimate processes) or the usage of wmic.exe and PowerShell cmdlets (Invoke-WmiMethod, Invoke-CimMethod) to execute processes on remote systems, as indicated by command line arguments specifying target nodes or computer names.
Detects suspicious PowerShell execution patterns involving encoded commands, hidden window styles, or common download cradles combined with code obfuscation techniques. This rule monitors PowerShell ScriptBlock Logging (Event ID 4104) for combinations of indicators often used by threat actors to evade detection, such as Base64-encoded strings, hidden execution flags, network download utilities, and script obfuscation techniques.
Detects unauthorized or suspicious use of Windows Management Instrumentation (WMI) for lateral movement and remote code execution. The rule monitors for common WMI exploitation vectors, including the use of wmic.exe for process creation, PowerShell or C# invocations of WMI/CIM methods (such as Win32_Process Create), WMI event subscription registration for persistence, and the execution of mofcomp.exe.
This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys where the configured value points to a file located in common user-writable or temporary directories (AppData, Temp, ProgramData) with an executable extension (.exe, .dll, .scr, .bat, .vbs, .ps1, .cmd). This pattern is a common technique used by adversaries to establish persistence by ensuring malicious code executes automatically upon user login or system startup.
This rule detects potential DNS tunneling activity by identifying DNS requests with suspicious characteristics, such as the use of TXT/NULL query types, high-entropy subdomains, or oversized queries. It further aggregates these suspicious requests per parent domain and flags scenarios where a high volume of requests or unique subdomains are observed, indicating possible data exfiltration or C2 communication.
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
KQL Query from file: Network detection - C2 domains and static key
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
KQL Query from file: JivaChat Installer - Full Chain
KQL Query from file: JivaChat Installer - Full Chain
KQL Query from file: JivaChat Installer - Full Chain
Detects execution of encoded commands in macOS terminal environments that originate from clipboard content mimicking a reCAPTCHA verification process. This pattern often involves users being social-engineered into pasting a malicious string that decodes a payload and pipes it directly into a shell interpreter (sh/bash/zsh). The rule monitors for the co-occurrence of base64/openssl decoding commands and shell execution pipes, while filtering out known legitimate software installation patterns.
Detects execution of encoded commands in macOS terminal environments that originate from clipboard content mimicking a reCAPTCHA verification process. This pattern often involves users being social-engineered into pasting a malicious string that decodes a payload and pipes it directly into a shell interpreter (sh/bash/zsh). The rule monitors for the co-occurrence of base64/openssl decoding commands and shell execution pipes, while filtering out known legitimate software installation patterns.
Detects HTTP POST requests directed to the URI path '/api/credentials' over the non-standard TCP port 8133, which is indicative of AMOS (Atomic macOS) Stealer exfiltrating stolen credentials to a C2 server.
Detects HTTP POST requests directed to the URI path '/api/credentials' over the non-standard TCP port 8133, which is indicative of AMOS (Atomic macOS) Stealer exfiltrating stolen credentials to a C2 server.
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
Detects inbound Microsoft Teams calls or chats originating from an external or federated tenant where the caller's display name mimics internal IT support or helpdesk personnel, a technique used in social engineering and vishing campaigns.


