Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation of a DLL file within the 'ProgramData\CrossDevice\' directory. This path is associated with a dangling COM InprocServer32 registration and does not exist by default. The creation of files in this location by non-privileged processes is indicative of staging malicious DLLs for exploitation of COM-based privilege escalation chains, specifically CVE-2026-66804 and CVE-2026-50343.
This rule detects the presence of Vidar Stealer version 2.0+ by identifying the specific ARX-based (Addition-Rotation-XOR) stream cipher implementation. The detection logic searches for stable cryptographic constants (FNV-1a prime and golden-ratio constants), unique per-build ARX transformation constants, and specific post-decryption artifacts in the file's binary content.
Detects the accumulator-based virtual machine (VM) skeleton used by Vidar Stealer (v2.0+) to obfuscate its internal configuration and strings. The rule specifically identifies a combination of bit-manipulation and arithmetic primitives (ROR, ROL, NOT, IMUL, ADD, SUB, XOR) acting as a dispatcher pattern within highly entropic executable sections, which is a characteristic behavioral artifact of the Vidar Stealer obfuscation engine.
Detects the presence of specific .NET deserialization gadget chain components (ExpandedWrapper, XamlServices, ObjectDataProvider, LosFormatter) within application traffic or logs, which are indicative of exploitation attempts targeting SharePoint pre-authentication remote code execution vulnerabilities like CVE-2026-65660.
Detects malicious HTTP POST requests targeting SharePoint servers that attempt to inject 'Register' directives into pages or manipulate WebPartPage ToolPane markup, indicative of attempts to bypass SafeControls or exploit vulnerable SharePoint features for code execution.
Detects JavaScript code within HTML pages designed to block browser developer tools (F12, Inspect, View Source) using keydown event listeners. This technique is commonly associated with ClickFix-style phishing campaigns to prevent users or security analysts from inspecting malicious page content or fake CAPTCHA overlays.
Detects network activity associated with the ErrTraffic malware, specifically targeting JSON-RPC 'eth_call' requests to Polygon blockchain smart contracts used for C2 resolution and subsequent DNS queries to known malicious domains used for C2 infrastructure.
Detects malicious exploitation attempts against the SharePoint WebPartPages.asmx SOAP endpoint. Attackers use this endpoint to bypass security patches by invoking template-parsing functions like GetWebPartPageConnectionInfo, which facilitates Register-directive injection and XamlServices deserialization chains for remote code execution.
Detects the execution of a malicious Electron-based installer masquerading as Anthropic's Claude AI (ClaudeOpus5-desktop.exe). The rule monitors for the specific filename or known malicious hashes, as well as the spawning of an embedded malicious loader process associated with the RevStealer infection chain.
Detects RevStealer malware attempting to use blockchain infrastructure for C2 communication or failover. The rules identify specific 'eth_call' JSON-RPC method calls to Polygon smart contracts containing hardcoded indicators, as well as TLS connections to known public RPC providers used as fallback C2 infrastructure.
Detects spoofed emails carrying a .patch attachment sent to a GitLab incoming-email merge-request address. Requires Microsoft's composite authentication verdict (CompAuth: fail) -- a lower-noise spoofing signal than raw SPF/DKIM/DMARC -- and excludes sender/recipient pairs already seen corresponding with that token address in the prior 30 days to suppress recurring legitimate contributors.
Detects spoofed emails carrying a .patch attachment sent to a GitLab incoming-email merge-request address. Requires Microsoft's composite authentication verdict (CompAuth: fail) -- a lower-noise spoofing signal than raw SPF/DKIM/DMARC -- and excludes sender/recipient pairs already seen corresponding with that token address in the prior 30 days to suppress recurring legitimate contributors.
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
This rule detects the creation or modification of a DLL file within the 'ProgramData\CrossDevice' directory, or the modification of a specific COM CLSID InprocServer32 registry key associated with 'CrossDevice.Streaming.Source.dll'. This behavior is indicative of potential COM hijacking or persistence mechanisms targeting the CrossDevice streaming framework.
Detects a suspicious behavior chain characteristic of information stealers like Vidar. The process first modifies the Windows Registry to disable the Windows Error Reporting (WER) UI (an anti-analysis technique to suppress crash dialogs) and shortly thereafter initiates an outbound network connection to a public IP, likely for C2 communication or data exfiltration.
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
Detects high-volume, broad enumeration of sensitive Microsoft Graph API endpoints (users, groups, directory objects, applications, and mail folders) from a single host or user. This behavior is indicative of automated reconnaissance or post-compromise discovery of cloud identity environments.
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
The following analytic detects potential data exfiltration using plain HTTP POST requests. It leverages network traffic logs, specifically monitoring the `stream_http` data source for POST methods containing suspicious form data such as "wermgr.exe" or "svchost.exe". This activity is significant because it is commonly associated with malware like Trickbot, trojans, keyloggers, or APT adversaries, which use plain text HTTP POST requests to communicate with remote C2 servers. If confirmed malicious, this activity could lead to unauthorized data exfiltration, compromising sensitive information and potentially leading to further network infiltration.
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
Detects GitHub repository actions (git.clone, oauth_authorization.create, repo.download_zip) from actor IPs not seen for that user in the prior 30 days, requiring either 3+ actions or activity across 2+ distinct repositories from the new IP within the same day. Aggregating to burst/multi-repo behavior (rather than alerting on a single new-IP event) filters out one-off false positives from travel, VPNs, or dynamic IP reassignment while still surfacing sustained anomalous access patterns consistent with account compromise or bulk exfiltration.


