Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation of specific forensic log files (browser_decryption.log, sends.log) within the %TEMP% directory. These files are indicators of the data collection stage performed by the Rapuncel infostealer prior to archiving and exfiltration.
Detects a suspicious sequence of events where a user's registered phone number or recovery contact method is updated, followed shortly by an MFA factor reset or new factor enrollment. This pattern is a common indicator of a SIM-swap attack, where an attacker intercepts SMS-based MFA codes after hijacking the victim's phone number.
Detects multiple MFA push notifications generated within a short timeframe for a single user during a Self-Service Password Reset (SSPR) flow. This behavior is indicative of an attacker attempting to perform MFA fatigue/push harassment to gain unauthorized access via SSPR or to bypass account security controls.
Detects anomalous account recovery or MFA reset activity performed by a single help-desk user account. A high volume of reset actions across numerous distinct users within a short duration is a key behavioral indicator of potential help-desk account compromise or insider abuse involving unauthorized account takeovers.
Detects multiple MFA push notifications generated within a short timeframe for a single user during a Self-Service Password Reset (SSPR) flow. This behavior is indicative of an attacker attempting to perform MFA fatigue/push harassment to gain unauthorized access via SSPR or to bypass account security controls.
Detects ZIP archives exceeding 100MB that contain specific DLL filenames often used for junk-padding to evade sandbox analysis. This technique is observed in brand-impersonation campaigns targeting users with fake security or authentication software lures.
Detects the staging of ChainScript files into specific, masquerading subdirectories within user AppData folders that mimic legitimate Windows system paths. This activity is indicative of the _scatter.ps1 script redistributing components such as the Node.js runtime, agent configuration, and helper utilities before execution.
Detects instances where common script interpreters (powershell.exe, cmd.exe, mshta.exe, etc.) are launched by developer-centric processes (node.exe, npm.exe, Code.exe) with suspicious command-line arguments often used for reconnaissance, payload downloading, or obfuscated command execution.
Detects the execution of known remote access or remote monitoring software (such as TeamViewer, AnyDesk, or ScreenConnect) on corporate-issued Windows endpoints. The rule triggers on process execution patterns associated with unauthorized remote control, specifically looking for indicators of unattended access or silent installation commonly used by overseas actors to remotely operate company-issued laptops assigned to fraudulently hired identities.
Detects instances where Microsoft Visual Studio Code (Code.exe) spawns common interpreters or command-line tools (such as node, python, cmd, or powershell) that are not associated with known internal VS Code process behaviors like renderer tasks or tunnel operations. This activity may indicate malicious use of the integrated terminal or extension execution contexts to execute unauthorized code.
Detects the execution of known remote access or remote monitoring software (such as TeamViewer, AnyDesk, or ScreenConnect) on corporate-issued Windows endpoints. The rule triggers on process execution patterns associated with unauthorized remote control, specifically looking for indicators of unattended access or silent installation commonly used by overseas actors to remotely operate company-issued laptops assigned to fraudulently hired identities.
Detects Node.js or Python processes exhibiting behavior characteristic of information-stealing malware (such as the WaterPlum suite: BeaverTail, InvisibleFerret, OtterCookie, StoatWaffle). The rule monitors for these processes accessing sensitive files related to browser credentials, cryptocurrency wallets, scanned identification documents, or performing collection activities like keylogging and screen capturing.
Detects the use of PowerShell cmdlets (Add-MpPreference or Set-MpPreference) to modify Microsoft Defender exclusions (paths, processes, or extensions). This behavior is often associated with adversaries attempting to evade security detection by excluding malicious files or processes from being scanned by Microsoft Defender.
Detects suspicious command-line patterns typically used for downloading or executing malicious payloads, such as curl, base64 encoding, and PowerShell web requests, when spawned directly from Node.js or Visual Studio Code processes. This behavior is associated with supply chain compromises and loader activity (e.g., WaterPlum/Contagious Interview) targeting development environments.
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
Detects user authentication events to recruitment, career, or applicant-tracking applications where the connection originates from an anonymizing proxy, VPN, or datacenter IP address. This behavior has been observed as a precursor to North Korean IT worker recruitment fraud, where attackers mask their true geographic location to gain unauthorized employment.
Detects Node.js or Python processes exhibiting suspicious behavior consistent with information-stealing malware (such as BeaverTail or InvisibleFerret). The rule monitors for these processes accessing sensitive files, including browser credentials, cookies, browser extension wallet settings, cryptocurrency wallet files, and various identification document image types, followed by the execution of archiving utilities (e.g., zip, rar, 7z) to stage the collected data for exfiltration.
Detects the creation or modification of registry entries within the 'HKCU\...\Run' hive that point to executables located in suspicious or atypical directories such as 'ProgramData', 'Users\All Users', or specific non-standard application paths often used by malware for persistence.
Detects the use of PowerShell to modify Microsoft Defender preferences by adding exclusion paths, processes, or extensions shortly after the creation of Registry Run keys. This sequence is characteristic of post-exploitation activity where an adversary establishes persistence and subsequently attempts to neutralize security software monitoring of their malicious payloads to avoid detection during future execution.
This rule detects the creation of a file within the SysWOW64 directory followed by an immediate modification or creation of a Windows Run registry key within a 10-minute window. This behavior is indicative of a persistence mechanism where a malicious file is dropped to a system directory and registered for execution at system startup or user logon.
