Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the presence or execution of a specific file hash associated with a known malicious campaign (KREMLIN/REF9334) that leverages a signed SentinelOne binary. This indicates potential abuse of trusted code-signing to bypass security controls.
Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
Detects PowerShell processes using the .NET System.IO.File methods (SetLastWriteTime, SetCreationTime, SetLastAccessTime) to modify file timestamps, a common anti-forensic technique to obfuscate file creation or modification times.
Detects PowerShell processes using the .NET System.IO.File methods (SetLastWriteTime, SetCreationTime, SetLastAccessTime) to modify file timestamps, a common anti-forensic technique to obfuscate file creation or modification times.
Detects PowerShell processes using the .NET System.IO.File methods (SetLastWriteTime, SetCreationTime, SetLastAccessTime) to modify file timestamps, a common anti-forensic technique to obfuscate file creation or modification times.
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
This rule detects HTTP requests directed at Microsoft Exchange Outlook Web Access (OWA) that contain suspicious 'fakePath' and 'fakePageName' parameters in the URI. These parameters are indicators of the 'GhostContainer' malware attempting to establish a socket forwarding proxy through the web server to facilitate command and control communications.
Detects anomalous MS_T120 channel binding and MCS handshake patterns characteristic of the BlueKeep (CVE-2019-0708) remote code execution vulnerability in Microsoft RDP services.
Detects anomalous MS_T120 channel binding and MCS handshake patterns characteristic of the BlueKeep (CVE-2019-0708) remote code execution vulnerability in Microsoft RDP services.
Detection rules identifying malformed RDP MCS Connect Initial PDUs and unusual service crashes following RDP connection attempts, both indicative of exploitation attempts against the CVE-2019-0708 (BlueKeep) vulnerability.
Bigbear V2 Ioc Hunt
Sigma
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
Page 275 of 1871

