Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
Detects anomalous sign-in patterns indicative of real-time MFA relay attacks, where a user principal authenticates successfully from multiple distinct IP addresses and geographical locations within a short time window (15 minutes), suggesting the active interception of credentials and MFA challenges by a Phishing-as-a-Service platform.
Detects anomalous sign-in patterns indicative of real-time MFA relay attacks, where a user principal authenticates successfully from multiple distinct IP addresses and geographical locations within a short time window (15 minutes), suggesting the active interception of credentials and MFA challenges by a Phishing-as-a-Service platform.
Detects anomalous sign-in patterns indicative of real-time MFA relay attacks, where a user principal authenticates successfully from multiple distinct IP addresses and geographical locations within a short time window (15 minutes), suggesting the active interception of credentials and MFA challenges by a Phishing-as-a-Service platform.
This rule detects a suspicious monetization pattern where a user account experiences a high-risk sign-in event, followed shortly (within 2 hours) by the creation or modification of inbox rules. This pattern is often indicative of account compromise, where an adversary configures mailbox rules (e.g., forwarding or redirection) to facilitate data exfiltration or financial fraud.
This rule detects a suspicious monetization pattern where a user account experiences a high-risk sign-in event, followed shortly (within 2 hours) by the creation or modification of inbox rules. This pattern is often indicative of account compromise, where an adversary configures mailbox rules (e.g., forwarding or redirection) to facilitate data exfiltration or financial fraud.
Detects a specific concealment behavior attributed to the 'com.corp.mdm' Android implant. The rule monitors for a sequence of events where the application disables its own launcher (main activity) to hide from the app drawer, immediately followed by the initiation of a foreground service that masquerades as a system notification ('Android System' title with 'System service running.' text).
Detects unauthorized or suspicious use of USSD codes by the corporate MDM agent to modify call-forwarding settings. This activity is indicative of a compromise where an attacker uses an MDM-controlled device to intercept calls or divert communications.
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
Detects cleartext HTTP POST requests to specific URI endpoints (/api/v1/devices/register or /api/v1/devices/heartbeat) known to be used by the Corp_MDM Android spyware for C2 communication, registration, or heartbeat signals.
Detects an Android device registration attempt to a known malicious C2 IP address using parameters characteristic of a mobile device management (MDM) implant. The rule looks for a POST request to a specific registration endpoint containing device identifiers like deviceId, manufacturer, model, and osVersion.
Detects an Android device registration attempt to a known malicious C2 IP address using parameters characteristic of a mobile device management (MDM) implant. The rule looks for a POST request to a specific registration endpoint containing device identifiers like deviceId, manufacturer, model, and osVersion.
Detects an Android device registration attempt to a known malicious C2 IP address using parameters characteristic of a mobile device management (MDM) implant. The rule looks for a POST request to a specific registration endpoint containing device identifiers like deviceId, manufacturer, model, and osVersion.
Detects HTTP beaconing and command-and-control (C2) communication patterns consistent with the 'Corp_MDM' Android spyware, specifically heartbeat check-ins, command polling, and result reporting to a known malicious C2 IP address.
Detects HTTP beaconing and command-and-control (C2) communication patterns consistent with the 'Corp_MDM' Android spyware, specifically heartbeat check-ins, command polling, and result reporting to a known malicious C2 IP address.
Detects HTTP beaconing and command-and-control (C2) communication patterns consistent with the 'Corp_MDM' Android spyware, specifically heartbeat check-ins, command polling, and result reporting to a known malicious C2 IP address.
Detects HTTP beaconing and command-and-control (C2) communication patterns consistent with the 'Corp_MDM' Android spyware, specifically heartbeat check-ins, command polling, and result reporting to a known malicious C2 IP address.
Detects the presence of known Vidar infostealer samples by matching file hashes against a list of identified malicious artifacts. The rule monitors for file creation events, process execution (both as the primary process and as an initiating process), and network activity originating from these known malicious files.
Detects the presence of known Vidar infostealer samples by matching file hashes against a list of identified malicious artifacts. The rule monitors for file creation events, process execution (both as the primary process and as an initiating process), and network activity originating from these known malicious files.
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.

