Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the loading of an unsigned or invalidly signed DLL from commonly abused user-writable directories (Temp, AppData, Public). This behavior is characteristic of DLL side-loading techniques, often used by threat actors like the Lazarus Group to execute malicious code via a legitimate, trusted application.
Detects Microsoft Office applications (Winword/Excel) spawning PowerShell or MSHTA with base64-encoded command-line arguments, followed by subsequent persistence mechanisms such as creating scheduled tasks or modifying Registry Run keys. This behavior is indicative of APT38 (BlueNoroff) and similar campaigns delivering banking Trojans via malicious Office macros.
This rule detects instances where Microsoft Word (winword.exe) or Microsoft Excel (excel.exe) initiate a PowerShell (powershell.exe) process containing command-line arguments typical of downloader stagers, such as 'IEX', 'DownloadString', or hidden execution flags. This behavior is a common indicator of macro-based delivery of malware, frequently observed in campaigns associated with FIN7/Carbanak and other threat actors utilizing Cobalt Strike or similar offensive frameworks.
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
Detects the creation of scheduled tasks (Windows), cron jobs (Linux), or systemd timers where the initiating process is a common scripting or runtime interpreter (e.g., Python, Node.js, PowerShell, Java). This activity is often indicative of persistence mechanisms being established by a compromised agent or script-based process.
Detects unauthorized creation or modification of AI agent system prompts, guardrails, or policy configuration files. This rule monitors for changes made by processes or users other than those identified as authorized CI/CD deployment agents or service accounts, helping to prevent unauthorized tampering with AI agent behavior or safety policies.
Identifies suspicious processes performing beacon-like network communications with rare external destinations. The rule detects consistent hourly activity intervals and high connection counts to endpoints rarely contacted by other devices in the organization, serving as a heuristic for automated C2 beaconing.
Detects the use of legitimate data transfer utilities (s5cmd, rclone) configured to exfiltrate sensitive document types (.doc, .pdf, .sql, etc.) to S3-compatible cloud storage. The rule correlates this activity with recent access to files containing sensitive credentials or configuration data, a pattern observed in double-extortion campaigns.
Detects execution of command-line tools commonly associated with system log clearing and secure file deletion. Specifically monitors for 'wevtutil' usage to clear logs, PowerShell commands to remove event log properties, and 'cipher /w' for permanent file data destruction.
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
Detects the installation of known AI-powered coding assistant extensions (e.g., Copilot, Tabnine, Cursor) on a device, followed by significant source-code repository cloning or archival activity by Git within two hours. This pattern is potentially indicative of intellectual property theft or sensitive source code exfiltration facilitated by a newly introduced AI tool.
Detects instances where a browser extension is installed, followed within a two-hour window by the browser process making network connections to generative AI service domains. This behavior is indicative of potential malicious browser extension activity, such as scraping or exfiltrating session/browsing data to third-party AI backend services.
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Detects a suspicious sequence where a process loads the .NET CLR (clr.dll or mscoree.dll) and shortly thereafter accesses specific low-prevalence file extensions (.raw or .pak) within high-risk directories (AppData/Local/Temp, ProgramData, or Users/Public). This behavior is characteristic of shellcode loaders (such as the WAV-shellcode loader) that decrypt and execute RAT payloads from obfuscated containers in memory. The rule intentionally excludes common desktop applications to minimize false positives.
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
Page 27 of 1866



