Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
Detects anomalous, high-frequency requests from a single source IP targeting sensitive NetScaler/Citrix ADC Gateway paths. This behavior is indicative of automated reconnaissance or vulnerability scanning often preceding exploitation attempts.
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
This rule detects HTTP POST requests to .php files containing suspicious PHP execution functions in the request body, such as 'system', 'eval', or 'shell_exec'. These patterns are indicative of an attempt to execute commands via an in-memory or injected PHP web shell on an F5 BIG-IP APM device.


