Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
Detects the creation of a Windows scheduled task via schtasks.exe where the initiating process is located in common user-writable temporary or non-standard directories (e.g., AppData, Temp, or Public folders). This behavior is often indicative of malicious persistence mechanisms being established by a dropper or stage-one malware payload.
Detects a behavioral chain where a process establishes persistence using a 'WindowsUpdate' Registry Run key or a scheduled task, followed within five minutes by an outbound network connection from the same process. The rule specifically excludes cases where a ZIP file was written to disk, identifying potential in-memory staging for exfiltration.
This rule detects outgoing HTTP POST requests that contain a ZIP file with a filename prefix of 'StolenData_' in the request body. This is a known behavior of the TokenGrabber stealer family, which exfiltrates collected victim data (e.g., browser credentials, session tokens) to a remote server, often via a Discord webhook or similar infrastructure.
TokenGrabber Builder: Webhook XOR/Base64 Obfuscation Artifacts - detects webhook.txt persistence, XOR 0x5A + Base64 webhook obfuscation, WEBHOOK_PLACEHOLDER injection, and the _x() decode routine used to recover the exfiltration endpoint
Detects unauthorized processes (excluding firefox.exe and explorer.exe) accessing or modifying sensitive Firefox browser profile files, specifically places.sqlite (history/bookmarks) and cookies.sqlite (session cookies). This activity is often indicative of credential or session hijacking attempts by malware or malicious scripts.
Detects a sequence of activity where a process queries Windows Registry keys related to installed Python versions, followed shortly by the invocation of Python-to-executable compilation tools like Nuitka or PyInstaller. This pattern is indicative of an adversary or developer performing interpreter discovery before compiling a payload into a standalone executable.
Detects a suspicious sequence of events where a process creates a scheduled task named 'WindowsUpdate' followed by execution of 'netsh' commands to dump wireless profiles or clear keys within a 15-minute window. This behavioral pattern is often associated with credential-stealing malware attempting to establish persistence and harvest sensitive information.
Detects unauthorized processes attempting to access Discord's local storage (LevelDB) where authentication tokens are stored, followed by a network request to the Discord API user validation endpoint, which is a pattern indicative of token extraction and liveness testing by malware.
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
Detects sensitive cPanel/WHM administrative commands or system file modifications occurring within one hour of a suspected authentication bypass event, indicative of potential post-exploitation activity related to CVE-2026-41940.
Detects network and DNS activity associated with the SideCopy threat group, specifically monitoring for connections to known C2 domains, C2 IP addresses, or the usage of port 5863 typically associated with the ReverseRAT backdoor.
Detects execution and network activity related to the PamStealer / Wavel malware campaign, including the JXA dropper and associated C2 infrastructure. The rule monitors for known malicious file hashes (e.g., JXA dropper, pkgunpack utility) and network connections to identified lure, distribution, and C2 domains and URLs used by the campaign.
Detects PamStealer-style browser credential theft on macOS. The detection logic identifies the forced termination of browser helper processes using 'pkill' (which releases SQLite file locks) followed by the execution of a 'KcHelper' binary that uses specific environment markers (e.g., KC_PASS) to bypass keychain authorization prompts and steal stored browser credentials.
Detects a successful login attempt by the user account 'p2pwn' targeting port 37777. Port 37777 is commonly associated with DVR/NVR surveillance equipment and is frequently targeted by brute-force attacks and botnets attempting to gain unauthorized access to embedded devices.
Detects network activity related to the exploitation of the CVE-2025-31702 vulnerability in Dahua P2P Relay services. The rules monitor for probe attempts, device parameter fetching (randsalt), serial number enumeration bursts, and successful no-auth channel responses, indicating a bypass of authentication mechanisms on vulnerable Dahua devices.
Detects exfiltration of sensitive information, including Dahua camera credentials and internal identifiers, to the Telegram Bot API over HTTPS. These rules monitor for specific API endpoints (/sendPhoto) and common credential patterns (Login:, Password:, Model:) or indicators (Shodan links, VKontakte references) within HTTP POST requests directed toward api.telegram.org.
Detects exfiltration of sensitive information, including Dahua camera credentials and internal identifiers, to the Telegram Bot API over HTTPS. These rules monitor for specific API endpoints (/sendPhoto) and common credential patterns (Login:, Password:, Model:) or indicators (Shodan links, VKontakte references) within HTTP POST requests directed toward api.telegram.org.
Detects the use of PowerShell to load .NET assemblies into memory using System.Reflection.Assembly::Load combined with indicators often associated with fileless payload execution, such as GZip decompression, AES decryption, or method invocation (EntryPoint.Invoke, GetType).
Detects attempts to impair or disable Microsoft Defender Antivirus through unauthorized exclusion paths, Registry modifications, tampering with protection settings, or forcing policy updates.
Detects command-line activity indicating an attempt to bypass or tamper with Anti-Malware Scan Interface (AMSI) functionality. The rule flags processes invoking GetProcAddress or LoadLibrary to resolve and manipulate AMSI-specific functions like AmsiScanBuffer or AmsiScanString within amsi.dll, a common technique for disabling runtime script scanning.


