Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
Detects anomalous, high-volume authentication failures originating from a single source IP address targeting multiple distinct internal devices within a short timeframe. This behavior is indicative of a password spraying or brute-force attack.
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
Detects Mimikatz binary or in-memory module used for credential harvesting following PaperCut RCE exploitation
Detects the execution of netscan.exe, a common network scanning tool often used by adversaries to enumerate network resources, hosts, and services within a compromised environment.
This rule detects attempts to patch critical Windows functions used for security instrumentation, specifically 'AmsiScanBuffer' within 'amsi.dll' (often for bypassing AMSI) or 'EtwEventWrite' within 'ntdll.dll' (often for disabling ETW logging). This activity is highly indicative of defensive evasion techniques used by malware or malicious actors to hide their behavior from security tools.
Detects access to sensitive files (KeePass databases, SSH private keys, and VPN configurations) by processes other than their designated applications. This behavior indicates potential credential harvesting or configuration exfiltration by unauthorized processes.
Detects instances where a process has been elevated on a Windows system, as indicated by specific log messages containing 'Process is elevated' within the command line or image file name fields.
Detects the creation of a scheduled task using 'schtasks.exe' configured to run as the SYSTEM account for a one-time execution. This behavior is often associated with persistence mechanisms or privilege escalation attempts where an adversary seeks to execute malicious code in a high-privileged context.
This rule detects the use of 'taskkill.exe' to terminate critical services, including security software (MsMpEng.exe), database processes (sql.exe, oracle.exe, sqlservr.exe), and common user applications (outlook.exe, onedrive.exe). This behavior is characteristic of the DragonForce ransomware, which disables protective services and applications before encryption to minimize interference and ensure successful file locking.
Detects unauthorized modification of the registry path 'HKCU\Software\Classes\ms-settings\Shell\Open\command'. This registry key is commonly hijacked by the 'fodhelper.exe' UAC bypass technique, where an attacker writes a malicious command to be executed with elevated privileges when the OS triggers the ms-settings protocol handler.
Detects the CRPx0 ransomware technique of unhooking ntdll.dll in memory. This is achieved by reading the ntdll.dll file from disk and overwriting the in-memory .text section with a clean, unhooked version to bypass EDR monitoring and execute direct syscalls.
Detects modifications to the Windows RunMRU registry key that include suspicious strings such as 'powershell', 'curl', or long base64-encoded sequences. This behavior is indicative of the 'ClickFix' technique, where users are socially engineered to paste and execute malicious commands directly into the Windows Run dialog.
Detects the execution of PowerShell encoded commands that result in the installation of known remote monitoring and management (RMM) software. This pattern is indicative of attackers, specifically those associated with Ransom Busters or similar affiliates, establishing persistent remote access to compromised systems.
Detects the creation of a Windows scheduled task configured to execute as the SYSTEM account using a one-time execution trigger. This combination is frequently used by adversaries for post-exploitation activities, such as lateral movement or persistence, as it allows for a single, immediate execution of a malicious payload with high-level privileges.
Detects the execution of the SoftPerfect Network Scanner tool (netscan.exe), which is often used by adversaries for reconnaissance to identify active hosts, open ports, and services within a network.
Detects the termination of critical processes, including security software (MsMpEng.exe), database services (sql.exe, oracle.exe, sqlservr.exe), and office productivity applications (excel.exe, outlook.exe, winword.exe). The sudden termination of these processes can indicate unauthorized attempts to disable security controls, disrupt database operations, or interfere with end-user activity.
This rule monitors Microsoft Teams communications for keywords related to passkey or Single Sign-On (SSO) configuration, which are common themes in social engineering and credential harvesting attacks. It correlates these messages with Windows logon events (Event ID 4624) for the sender to identify potentially compromised accounts or active phishing attempts originating from within the environment.
Detects DNS resolution requests for graph.microsoft.com initiated by a python interpreter (python.exe, python3.exe, or pythonw.exe). This activity may indicate a script or custom tool communicating with Microsoft Graph API, which is frequently used for data collection, exfiltration, or cloud service interaction in adversarial campaigns.
Page 271 of 1871

