Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule monitors email traffic to detect scenarios where a single recipient is receiving a large volume of emails (at least 30 messages) from a high number of unique senders (at least 15) within a one-hour window. This behavior is indicative of a potential bulk spam or phishing campaign targeting a specific mailbox, which may be attempting to overwhelm the recipient or bypass traditional filters through volume.
Detects potential Adversary-in-the-Middle (AiTM) phishing activity where a user successfully authenticates to Microsoft 365 with MFA, followed shortly by a session from a different IP address reusing the same session ID without a repeated MFA challenge.
This rule detects potential MFA phishing attempts by identifying access to known malicious domains used for MFA credential harvesting within email communications and network traffic. It flags instances where users interact with domains masquerading as legitimate multi-factor authentication setup or registration services.
Detects the use of the Windows certutil utility to decode Base64-encoded files into executable, library, or script formats. This technique is commonly used by adversaries to decode malicious payloads that were dropped on a system in an encoded form to bypass signature-based security controls.
Detects the use of bitsadmin.exe to create or modify Background Intelligent Transfer Service (BITS) jobs, specifically when combined with the /setnotifycmdline flag. This technique is used by adversaries to download malicious payloads and trigger their execution upon job completion, often bypassing network security controls that might otherwise flag traditional download-and-execute activity.
Detects suspicious execution patterns of rundll32.exe, including usage for JavaScript execution, control panel file abuse, potential credential dumping using comsvcs.dll, and execution from common user-writable temporary directories.
Detects the invocation of Windows Subsystem for Linux (WSL) binaries (wsl.exe or wslconfig.exe) using command-line arguments that enable arbitrary command execution, such as -e, --exec, or shell interpreters (bash -c, sh -c), or web-based retrieval tools like curl/wget. This technique is often used to execute commands or download payloads within a Linux environment on Windows, potentially bypassing security controls focused on native Windows processes.
This rule detects the loading of known-vulnerable or malicious kernel drivers (BYOVD) followed by the termination of major EDR or security-related processes on the same host within a 10-minute window. This behavior is indicative of an adversary attempting to disable security controls to evade detection after achieving kernel-level privileges.
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
Detects a suspicious sequence of network events consistent with a credential-harvesting campaign abusing the FedCM (Federated Credential Management) API. The rule identifies the initial fetch of a malicious loader script from a lookalike domain (pdf.gusercontent.com), followed closely (within 5 minutes) by a redirect to Google's legitimate 'EmbeddedSetup' sign-in flow containing an email parameter.
Detects an account takeover chain where a device loads a malicious JavaScript component ('load-addon.js') in a browser session, followed by repeated attempts to bypass bot detection mechanisms (targeting Google's 'errors/robot.png') as the payload attempts to force authentication challenges or password resets.
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
This rule detects the presence of the malicious 'pdf-para-texto@extensao.local' Firefox extension on disk. This extension is known to perform browser-based credential interception by patching the WebAuthn PublicKeyCredential interface at document_start on Google-related domains to facilitate account takeover.


