Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects modifications to Microsoft Exchange mailbox folder permissions where the 'Default' user is granted 'Owner' access. This activity, which may involve operations such as 'UpdateFolder', 'Add-MailboxFolderPermission', or 'Set-MailboxFolderPermission', is a known server-side persistence mechanism. By granting 'Owner' rights to the 'Default' user, an attacker can bypass standard authentication and device-level controls to access mailbox contents, often following initial exploitation such as OWA XSS.
Detects the spawning of common administrative or script-execution tools as child processes from SharePoint-related processes (w3wp.exe or OWSTIMER.EXE). This behavior is often indicative of exploitation attempts targeting SharePoint application pools to execute arbitrary code.
Detects instances where FortiClient EMS management daemon processes (FCMDaemon.exe, FortiClient_Server.exe, or FCMWebServer.exe) spawn suspicious child processes often associated with living-off-the-land techniques, such as command shells, scripting interpreters, or system administrative utilities.
Detects post-exploitation indicators of CVE-2026-62911, an authentication-bypass-by-capture-replay vulnerability in Microsoft Exchange. The rule identifies anomalous behavior following a potential bypass: either the assignment of the ApplicationImpersonation management role or a single impersonation session accessing an abnormally high number of distinct mailboxes (FolderBind, MessageBind, or SendAs).
Detects the loading of Python DLLs (python36.dll or python37.dll) from suspicious, non-standard user-writable directories such as Downloads, Temp, or AppData, which may indicate a DLL sideloading attempt.
Detects the use of PowerShell to modify Windows Defender exclusions by adding a path or process located in user-controlled directories (Downloads, Temp, AppData). This behavior is characteristic of adversaries attempting to suppress security alerts for malicious binaries masquerading as legitimate software.
Detects suspicious command execution patterns on macOS frequently associated with the 'ClickFix' technique utilized by AMOS (Atomic macOS Stealer). This includes piping base64-encoded curl downloads directly to a shell, utilizing osascript to execute shell commands, and modifications to LaunchAgents for potential persistence.
Detects unauthorized or suspicious configuration changes on Cisco IOS XR devices, specifically targeting the creation of SPAN/mirroring sessions, ACL modifications to bypass traffic filtering, and changes to AAA or local user authentication settings. These patterns are consistent with post-compromise activities by adversaries seeking persistence and traffic interception.
Detects incoming HTTP requests to FortiSandbox administrative or management endpoints that contain suspicious shell metacharacters and command-injection patterns. These patterns are indicative of attempts to exploit CVE-2026-25089, an unauthenticated remote command injection vulnerability in the FortiSandbox Web UI.
Detects execution of netcat with the "-e" flag followed by common shells. This could be a sign of a potential reverse shell setup.
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
Detects potential embedding inversion or extraction attempts by identifying callers exhibiting abnormally high volumes of similarity or vector search queries against RAG-enabled vector stores or cognitive search APIs within a short timeframe.
Detects potential embedding inversion or extraction attempts by identifying callers exhibiting abnormally high volumes of similarity or vector search queries against RAG-enabled vector stores or cognitive search APIs within a short timeframe.
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
Detects the use of native Windows utilities such as vssadmin.exe, wmic.exe, and diskshadow.exe to delete volume shadow copies. This is a common technique used by ransomware and other malware to prevent system recovery.
This rule detects modification of the Windows Registry to disable the Windows Firewall. Specifically, it monitors for EventID 4657 (A registry value was modified) where the 'EnableFirewall' value is set to '0' within the FirewallPolicy service registry path, indicating an attempt to disable the host-based firewall.
Detects the creation of a DLL file within the 'ProgramData\CrossDevice\' directory. This path is associated with a dangling COM InprocServer32 registration and does not exist by default. The creation of files in this location by non-privileged processes is indicative of staging malicious DLLs for exploitation of COM-based privilege escalation chains, specifically CVE-2026-66804 and CVE-2026-50343.
This rule detects the presence of Vidar Stealer version 2.0+ by identifying the specific ARX-based (Addition-Rotation-XOR) stream cipher implementation. The detection logic searches for stable cryptographic constants (FNV-1a prime and golden-ratio constants), unique per-build ARX transformation constants, and specific post-decryption artifacts in the file's binary content.
Detects the accumulator-based virtual machine (VM) skeleton used by Vidar Stealer (v2.0+) to obfuscate its internal configuration and strings. The rule specifically identifies a combination of bit-manipulation and arithmetic primitives (ROR, ROL, NOT, IMUL, ADD, SUB, XOR) acting as a dispatcher pattern within highly entropic executable sections, which is a characteristic behavioral artifact of the Vidar Stealer obfuscation engine.



