Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
Detects HTTP requests containing malicious JDBC strings targeting PaperCut NG/MF print management software, which are indicative of attempts to exploit authentication bypass and remote code execution vulnerabilities (CVE-2026-81578, CVE-2026-82078).
Detects HTTP POST requests directed at Grav CMS endpoints where the __unique_form_id__ parameter contains directory traversal sequences (e.g., ../). This behavior is indicative of attempted exploitation of CVE-2026-42608, aimed at bypassing file system restrictions to write files to unauthorized locations outside the application's expected form data directory.
This rule detects malicious HTTP POST requests attempting a path traversal attack against Grav CMS, specifically targeting the __unique_form_id__ parameter. The rule looks for directory traversal sequences ('..') following the parameter, which is characteristic of attempts to read sensitive files outside the intended web directory.
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
Detects SectopRAT (Arechclient2) .NET RAT binaries deployed via tampered libcef.dll / JetBrains helper DLL sideloading that harvest browser credentials, cookies, credit card data, and files. Tightened to require combined sideload+family+target indicators plus .NET CLR import evidence, avoiding standalone generic strings.
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
Detects HTTP GET requests to '/api.php?t=' containing a 13-digit timestamp identifier, followed by a response body containing 'download_link'. This pattern is indicative of the SilverFox malware relaying instructions or stage-two payload delivery.
Detects DNS queries, TLS SNI headers, and HTTP host headers associated with the known exfiltration domain 't.m-kosche.com' linked to the Mini Shai-Hulud malware.
Detects unauthorized execution of a Bun runtime executing an 'index.js' payload within a GitHub Actions workflow context, specifically targeting known compromised action paths (e.g., issues-helper, maintain-one-comment). The detection requires correlation with either sensitive environment/secret access or anomalous outbound network activity originating from the same process, indicating potential credential theft or C2 communication by a malicious CI/CD pipeline component.
Detects emails that appear to have been injected or sent using the 'swaks' SMTP testing tool rather than a standard Mail User Agent (MUA). The rule identifies this activity by looking for the 'swaks' signature in the 'X-Mailer' header or by matching a specific 'Message-Id' pattern typical of swaks.
Detects incoming email messages where the Reply-To header address domain differs from the Sender From address domain. This technique is commonly used in phishing attacks to redirect victim replies to an attacker-controlled mailbox while maintaining a spoofed appearance in the original sender field.
This rule detects potential phishing attempts where the sender's display name is formatted as an email address and the sender's domain uses a capital 'I' character to mimic a well-known service provider (typosquatting/homoglyph attack), such as 'gmaiI.com'. It identifies discrepancies between the actual sender domain and the normalized domain name after character replacement.
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.

