Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
Detects delivery and execution artifacts associated with the BlueMoon CVE-2026-85046 V8 type-confusion exploit. The rule monitors for known exploit-related file names (e.g., driver-html.js) and characteristic string indicators (e.g., v8ctf_exp_attempt, addrof, fakeobj) across file system, process execution, and network telemetry.
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
This rule detects potential malicious activity by monitoring for known malicious file hashes (MD5) across file and process events, and correlating them with known Command and Control (C2) infrastructure communication patterns, including specific IP addresses and URI paths.
Detects the presence or execution of a specific file hash associated with a known malicious campaign (KREMLIN/REF9334) that leverages a signed SentinelOne binary. This indicates potential abuse of trusted code-signing to bypass security controls.
Detects Remote Desktop Protocol (RDP) connections established over known suspicious high ports or to specific remote IP addresses associated with known C2 operator infrastructure (SpiceRAT). This behavior indicates potential remote interactive access by an adversary.
Detects the loading of 'libcurl.dll' or related DLL patterns from suspicious directories such as '\Microsoft\Crypto\RuntimeBroker\', often associated with process masquerading or side-loading activities. The rule also monitors for the execution of suspicious binaries ('Tax_Notice_45594.exe') or binaries that mimic 'Notepad++' metadata from within these paths.
Detects outbound network connections to known command-and-control (C2) infrastructure associated with SpiceRAT, including specific malicious IP addresses and domain names used for decoy content delivery.
This rule detects outbound network connections from internal devices to a list of known malicious IP addresses associated with adversary command and control infrastructure. The rule specifically monitors connections over common ports, potentially indicating established communication with malicious servers.
Detects outbound network connections to 'acrobat-updater.com' involving suspicious API paths that mimic the Adobe Acrobat updater. This may indicate an attempt by an adversary to masquerade malicious command and control or data exfiltration as legitimate update traffic.
Detects attempts to perform a DCSync attack by monitoring for Windows Event ID 4662 where sensitive Directory Replication Service (DRS) rights are requested. This attack pattern, often associated with tools like Mimikatz, allows an adversary to pull password data from Active Directory. The rule excludes requests from known domain controller accounts.
Detects the execution of PowerShell with specific command-line arguments (-NonInteractive, -NoProfile, -Command) often used by the Bird Agent backdoor or similar malicious scripts to execute code silently without user intervention or profile configuration.
Detects the creation of suspicious DLL or ASPX files within Microsoft Exchange or IIS directories that are associated with the GhostContainer backdoor, commonly used by the NightEagle threat actor for maintaining persistence.
Detects DCSync activity, a method of credential dumping, by identifying DRSUAPI 'GetNCChanges' replication requests originating from a host that is not a recognized Domain Controller. The rule uses Active Directory replication GUIDs, explicit operation logs, and enriches host data to filter for illegitimate sources.
Detects unauthorized child processes spawned by ScreenConnect client binaries. The rule specifically looks for files created or modified within 60 seconds prior to execution, which is indicative of attackers leveraging an authentication bypass vulnerability (CVE-2026-84869) to transfer and execute malicious payloads via an active remote access session without requiring additional user interaction or authentication.
Detects a multi-stage infection chain involving communication with known malicious infrastructure ('mnoskemp.beer'), staging and extraction of password-protected archives using '7za.exe' in temporary directories, installation of a spoofed OBS Studio MSI package, and subsequent DLL side-loading of malicious libraries (e.g., 'obs.dll', 'WSql-2.dll') by the 'obs64.exe' process when initiated from outside legitimate installation paths.
This rule detects potential exploitation attempts against PaperCut servers by identifying high-frequency, consistent-interval network requests directed at PaperCut-specific URI patterns and ports, or associated with known vulnerability identifiers (CVE-2026-81578, CVE-2026-82078). The rule employs statistical analysis to identify potential automated scanning or exploitation activity, filtering out known geographic regions associated with lower-risk or irrelevant traffic.
Page 255 of 1871


