Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of the Rubeus tool, a C# toolkit used for interacting with the Kerberos protocol. The rule specifically monitors command-line arguments and process names associated with common Kerberos exploitation tasks such as Kerberoasting, Golden/Silver Ticket forging, and ticket manipulation.
This rule detects unauthorized attempts to perform Active Directory replication requests (DCSync) by monitoring for specific Event IDs (4662), activity types (DsGetNCChanges, DRSUAPI), and known Directory Replication Service (DRS) UUIDs. It specifically flags requests originating from non-Domain Controller assets or workstations, which is a common indicator of credential dumping via tools like Mimikatz.
This rule monitors for execution patterns associated with the Evil-WinRM tool, a common post-exploitation framework used for remote command execution via WinRM. It identifies suspicious command-line arguments in PowerShell, the creation of configuration files typical of the tool, and network connections to WinRM ports initiated by common execution binaries like PowerShell or Ruby.
Detects file creation, modification, or renaming events initiated by ScreenConnect (ClientService.exe or WindowsClient.exe) that are not accompanied by associated user confirmation, consent, or file transfer events. This can indicate an unauthorized or silent file manipulation by a remote actor using the ScreenConnect tool.
Detects multiple defense evasion techniques typically associated with the Monkey ransomware family, including clearing Windows Event Logs, clearing PowerShell command history, tampering with AMSI and ETW, modifying Microsoft Defender exclusions, and disabling Task Manager or CMD via registry keys.
Detects the execution of the Rubeus tool, a widely used offensive security tool for Kerberos manipulation, including ticket requests, pass-the-ticket, and credential dumping.
This rule detects potential credential dumping activities by monitoring for the execution of Mimikatz or command-line arguments associated with credential extraction (e.g., 'sekurlsa::logonpasswords'). Additionally, it monitors for suspicious process access attempts to 'lsass.exe' with specific high-privileged access masks often used by credential dumping tools to read process memory.
This rule detects suspicious child processes, such as shells and system utilities, spawned by PaperCut application processes (pc-app.exe, pc-app-service.exe) or associated Java/Tomcat service components. This pattern is commonly observed during exploitation attempts targeting PaperCut Print Management software, where attackers use web services to gain command execution.
Detects potential SQL injection attempts by monitoring for 'INSERT INTO' SQL commands executed via command-line arguments. The rule specifically looks for operations targeting user or role tables and including administrative keywords, originating from database or application-related processes like mysql or java.
This rule detects file access events targeting sensitive files such as credential stores, configuration files (e.g., .env, config.yaml, wallet.dat), and AWS credential files. This is indicative of an adversary searching for stored secrets or configuration data to facilitate further lateral movement or privilege escalation. The rule excludes common developer tools like code editors and file explorers to reduce noise.
Detects when ScreenConnect client processes (ClientService.exe or WindowsClient.exe) spawn child processes that are not part of the standard ScreenConnect application suite. This behavior is indicative of unauthorized use of remote access tools for command execution or lateral movement.
This rule performs a hunting activity across multiple telemetry sources (Network, Email, Endpoint) to detect known indicators of compromise (IOCs) associated with Anthropic threat intelligence reporting (September 2026). It looks for specific malware file names, command-line patterns, service installations, phishing email addresses, and C2 communication URLs.
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
Page 254 of 1871

