Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects scenarios where a user account modifies Conditional Access (CA) policies (specifically targeting user or group inclusion/exclusion settings) within one hour of that same user account modifying authentication method policies. This pattern is potentially indicative of an adversary weakening security controls by adjusting authentication requirements and subsequently tampering with CA policies to maintain persistence or bypass MFA.
Detects Large Language Model (LLM) responses that contain instructions designed to propagate the current prompt to other users, systems, or agents. This pattern is indicative of a self-replicating prompt worm, which aims to spread malicious instructions across an AI ecosystem by leveraging the model's ability to generate text that instructs subsequent interactions.
Detects anomalous process spawning behavior initiated by Python interpreters (pip/conda) on machine learning developer or training hosts, which may indicate a supply chain compromise where a malicious package executes code during or shortly after installation.
This rule detects three distinct suspicious behaviors related to potential file manipulation and persistence mechanisms: 1. Use of 'copy /b' command to reconstruct files from fragments (e.g., header.doc, body.doc), commonly associated with file joining or data reconstruction. 2. File access within '_rels' directories targeting document fragments, often used in malicious document analysis or extraction. 3. Execution of 'Windowsupdate.exe' from the 'AppData\Local' directory, a technique often used for masquerading as a legitimate Windows service to establish persistence.
Detects the execution of the Windows FTP client (ftp.exe) using command-line arguments that include scripts (-s:), initiated by unconventional parent processes such as explorer.exe or cmd.exe. This behavior is often associated with the execution of automated FTP scripts for data exfiltration or malware delivery.
Detects Azure sign-in events claiming successful hardware-key or FIDO2 authentication where the authentication issuer is not part of a known-good allow-list. This behavior is indicative of a rogue MFA provider, such as the TrustSink attack, which issues forged tokens claiming MFA requirements were satisfied.
This rule monitors for indicators of compromise (IOCs) associated with the TrustSink rogue MFA provider, specifically tracking the domain 'trident-sip-filter.ngrok-free.dev' and its associated OIDC discovery path. It aggregates signals from sign-in logs, audit logs, DNS queries, and network proxy traffic to identify attempts to interact with this malicious infrastructure.
Detects instances where an AI agent or LLM invokes a high-privilege or sensitive tool (such as code execution, outbound HTTP, or credential store access) immediately following a prompt that exhibits characteristics of prompt injection or jailbreaking. This behavior matches MITRE ATLAS pattern AML.T0053, suggesting an attempt to use the AI agent as a pivot or execution vehicle for unauthorized actions.
Detects anomalous, exploratory query patterns by an API key or service account against an AI model inference API. High distinct resource access volume in a short timeframe, potentially combined with off-hours activity, indicates reconnaissance phases such as output-ontology or model-family enumeration, which may precede adversarial-example crafting or verification attempts.
Detects recovered scripts/payloads that harvest environment variables, API keys, bearer tokens, and Kubernetes secrets/configmaps into a variable named LOOT
This rule detects potentially malicious activity where an identity performs enumeration of Kubernetes secrets or configmaps and subsequently performs a search action within Slack from the same IP address within a one-hour window. This behavioral pattern is indicative of post-breakout reconnaissance, where a compromised identity or token is used to exfiltrate sensitive cloud configuration data and then perform internal reconnaissance in SaaS collaboration tools to identify further targets or credentials.
Detects suspicious processes frequently polling Hugging Face repository endpoints (discussions, raw files, commits). This behavior is characteristic of adversaries using public code/dataset hosting services as a covert command-and-control (C2) channel to fetch instructions or exfiltrate data, bypassing traditional network filters by blending in with legitimate developer traffic.
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
This rule detects potentially malicious emails that impersonate Microsoft account security notifications or security advisories. It looks for emails with specific social engineering themes in the sender name, sender address, or subject line, accompanied by .zip attachments that contain suspicious file names related to cybersecurity warnings or OTP abuse, which are common lures for malware delivery.


