Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects egress to the NeedyMantis C2 domain corp.tripswithengine[.]com across three vantage points: TLS SNI (port 443), DNS resolution, and HTTP Host header. Each content match is anchored to the start of its buffer ('startswith') so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') cannot match — only this exact domain or a genuine subdomain of it triggers.
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
The EntraIdSignInEvents table exposes the JA4 fingerprint in the GatewayJA4 field. But looking at the complete fingerprint alone does not tell us much. The interesting part starts when we break it down. With a simple KQL query, we can separate the TLS version, SNI, number of cipher suites, extensions and ALPN, together with the cipher and extension hashes. Then we can see how many sign-ins, users, IPs and countries are behind each JA4. The idea is simple: understand what is normal first, then look for what is different.
Detects the execution of PowerShell or PowerShell ISE where the parent process is the console host (conhost.exe) and the command-line arguments are either missing, empty, or represent an bare execution of the binary. This pattern is commonly associated with fileless execution techniques where attackers attempt to hide command-line arguments or evade logging.
Detects execution patterns indicative of 'ClickFix' social engineering, where a user is tricked into copying a command to their clipboard and executing it directly in a terminal. The rule monitors for processes that read clipboard contents (via PowerShell or clip.exe) and simultaneously invoke shell interpreters to execute the retrieved data.
Detects unauthorized processes attempting to access sensitive browser profile files, such as login credentials, cookies, and session state files. This behavior is indicative of credential harvesting or session theft by malicious software.
Detects execution of rundll32.exe or regsvr32.exe when spawned by powershell.exe or mshta.exe, specifically targeting DLLs located in common user-writable or temporary directories (AppData, ProgramData, Downloads). This pattern is consistent with the delivery of CastleLoader shellcode loaders following ClickFix-style social engineering lures.
Detects the deployment of NetSupport Manager (client32.exe) or related components when initiated by common scripting interpreters such as PowerShell, MSHTA, or CMD. This behavior is indicative of a ClickFix-style social engineering attack where a user is coerced into executing malicious commands to deploy remote access tools.
This rule detects illicit OAuth consent grant events where an application is granted high-risk delegated permissions. This behavior is indicative of consent phishing or 'ConsentFix' tradecraft, where attackers trick users into granting permissions to a malicious application, thereby enabling unauthorized access to mail and file data.
This rule detects illicit OAuth consent grant events where an application is granted high-risk delegated permissions. This behavior is indicative of consent phishing or 'ConsentFix' tradecraft, where attackers trick users into granting permissions to a malicious application, thereby enabling unauthorized access to mail and file data.
Detects the use of legitimate Windows system binaries (LOLBins) such as curl.exe, certutil.exe, or bitsadmin.exe to download files. These binaries are monitored when spawned directly from common entry-point processes like explorer.exe, cmd.exe, or powershell.exe, which is characteristic of second-stage payload retrieval in ClickFix social engineering campaigns.
Detects Azure AD / Entra ID sign-in events that utilize the OAuth 2.0 device code authentication flow. This protocol, designed for input-constrained devices, is frequently exploited by adversary-in-the-middle phishing kits (e.g., EvilTokens) to trick users into authorizing a malicious session, effectively bypassing traditional MFA by obtaining an active session token.
This rule detects indicators of Browser-in-the-Browser (BitB) phishing attacks within web proxy traffic. It monitors for suspicious HTML markup mimicking browser UI elements, such as fake title bars and URL bars, as well as specific window dimensions and authentication lures that deviate from known legitimate identity provider patterns.


