Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
This rule monitors for user interactions with specific domains and URLs known to be associated with suspicious or malicious activity. It aggregates data from multiple sources, including email clicks (UrlClickEvents), device network activity (DeviceNetworkEvents), device browser events (DeviceEvents), and DNS queries (DnsEvents), to identify potential exposure to these indicators of compromise.
Detects the use of PowerShell's Start-Sleep cmdlet with a duration of 3 minutes or longer within process command lines. This technique is commonly used by malware, such as ClickFix-style droppers, to bypass sandbox time-based analysis by delaying execution until the sandbox timeout period has elapsed.
Detects execution chains where explorer.exe (acting as the Run dialog host) spawns suspicious processes like mshta.exe, powershell.exe, or cmd.exe with command lines containing URL indicators (http), common payload filenames (rtdx.dat), or specific IP address strings associated with known ClickFix social-engineering campaigns.
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
Detects the execution of PowerShell commands that utilize a combination of 'iex' (Invoke-Expression) and obfuscated strings typical of download cradles. The rule looks for escaped double quotes inside the command line and specific regex patterns that match common obfuscation techniques used to hide malicious URLs or script components.
Detects the execution of standard Windows command-line utilities (cmd.exe, wmic.exe, powershell.exe, fsutil.exe, vol.exe) used to query local volume information, such as name and serial number. This behavior is frequently associated with environment fingerprinting or sandbox evasion, particularly when executed by suspicious processes like mshta.exe as part of initial infection chains such as ClickFix payloads.
Detects execution chains where explorer.exe (acting as the Run dialog host) spawns suspicious processes like mshta.exe, powershell.exe, or cmd.exe with command lines containing URL indicators (http), common payload filenames (rtdx.dat), or specific IP address strings associated with known ClickFix social-engineering campaigns.
Detects the execution of mshta.exe with a command line involving remote HTTP connections or suspicious file extensions (.dat), which are often used by adversaries to proxy the execution of malicious scripts or HTA files.
This query provides high-fidelity, post-exploitation hunting for CVE-2026-69730 by catching unauthorized child processes spawned from the Windows DNS Server engine (dns.exe).
Because dns.exe runs natively as NT AUTHORITY\SYSTEM and almost never executes external binaries during normal operations, filtering out known OS noise (conhost.exe and werfault.exe) flags potential RCE breakouts and privilege escalation with near-zero false positives.
Because dns.exe runs natively as NT AUTHORITY\SYSTEM and almost never executes external binaries during normal operations, filtering out known OS noise (conhost.exe and werfault.exe) flags potential RCE breakouts and privilege escalation with near-zero false positives.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy the Active Directory database file (ntds.dit) from the shadow copy. This pattern is commonly used by adversaries to perform offline credential dumping.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy the Active Directory database file (ntds.dit) from the shadow copy. This pattern is commonly used by adversaries to perform offline credential dumping.
This rule monitors for the presence or execution of files matching a known set of SHA256 hashes associated with the 'DXSCAN' malware, utilizing both device file and process events.
This rule monitors process creation, file system activity, and HTTP logs for indicators associated with the 'GHOST-VAULT' or 'GHOST-CRED' threat activity. It specifically triggers on files or paths containing 'GHOST-VAULT-', processes named 'ghost_' or containing 'ghost_' in the command line, and HTTP requests containing 'GHOST-CRED/3.0', 'GHOST-VAULT/', or 'GHOST/0day'.
Detects execution of potentially suspicious processes ('Launcher.exe' or 'GapiUpdate.exe') originating from ClickOnce-related processes ('dfsvc.exe' or 'rundll32.exe' with 'dfshim.dll'). ClickOnce is often abused to proxy execution of malicious code, allowing adversaries to execute applications from user-writable directories without administrative privileges.
This rule detects the execution of NetSupport Manager related files, specifically 'client32.exe', or the presence of 'NetSupport' or 'Manager.zip' in command lines. NetSupport is a legitimate remote administration tool that is frequently abused by adversaries to maintain persistence and remote control over compromised hosts.
Detects the execution of PowerShell or pwsh with encoded command arguments containing a long base64 string, often used by attackers to hide malicious scripts from command-line logging and basic static analysis.
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
Page 258 of 1871



