Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous DNS queries with high-entropy or encoded labels that exceed 40 characters in size, potentially indicating DNS tunneling used for Command and Control (C2) communication.
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
Detects anomalous network behavior consistent with the PolinRider malware, which uses public Ethereum JSON-RPC endpoints and blockchain explorers (e.g., Etherscan.io) as a dead-drop resolver for command-and-control (C2) communication. The rules monitor for specific RPC methods (eth_getTransactionByHash, eth_call, eth_getBalance) over HTTP/TLS and DNS resolution queries to known blockchain explorer infrastructure.
Detects network activity associated with NetSupport Manager remote access software, specifically monitoring for connections to known malicious domains and infrastructure, as well as recurring beaconing patterns indicative of command-and-control behavior.
Detects network communication to a known malicious IP address (45.32.253.166) associated with the PIVOTPIPE RAT using Cobalt Strike C2 beaconing patterns. The rule identifies TCP connections, HTTP GET requests for beacon check-ins, and HTTP POST requests for task responses.
Detects malicious tampering with GitHub Actions workflows by monitoring for two specific patterns within an hour: the addition of automatic push triggers for the main branch alongside the removal of manual approval gates, or rapid sequential commits that rewrite workflows to facilitate an unattended publish of a package. This rule also integrates with npm registry publish events to identify potential malicious distribution of compromised packages like @dforge-core/dforge-mcp.
Detects the creation of files named 'parser.js' or 'loader.js' within hidden or suspicious VSCode directories (e.g., .npm/.vscode/ or AppData/VSCode/). The detection also flags potential signs of malicious intent, such as the existence of a 'package.json' file nearby or the presence of 'tokenapp' in the file path, which are often indicative of the GHAPPIER implant behavior.
Detects the execution of rundll32.exe with a command line containing 'DavWWWRoot', indicating the loading of a DLL from a remote WebDAV share. This is a common technique used by attackers to execute remote malicious code while bypassing local execution policies or attempting to evade local file-based detection.
Detects anomalous, high-frequency access to clipboard APIs (GetClipboardData/SetClipboardData) by non-standard, unrecognized processes. The rule specifically monitors for patterns consistent with clipper malware, which polls the clipboard for cryptocurrency address formats and replaces them with attacker-controlled addresses.
This rule identifies processes that delete themselves shortly after execution. It joins process creation events with file deletion events on the same device, filtering for cases where the initiating process file name, ID, and hash match the deleted file, and where the deletion occurs within 120 seconds of the process creation. This behavior is commonly associated with malware or adversary tools attempting to remove traces of their activity.
Detects instances where a repository's GitHub CI/CD workflow, git configuration, or repository settings are modified, followed shortly thereafter by an npm package publish event. This behavior is indicative of a supply chain compromise where an adversary modifies workflow files to auto-publish malicious versions of a package.
KQL Query
Detects the execution of PowerShell via explorer.exe (typically initiated through the Windows Run dialog) where the command line references a WebDAV UNC path (containing DavWWWRoot). This behavior is characteristic of 'ClickFix' social engineering attacks, where users are coerced into copying and pasting commands into the Run dialog that trigger remote script execution.
Detects malicious shell commands attempting to perform supply-chain persistence via environment variable manipulation in CI/CD environments. The rule identifies processes injecting BASH_ENV into GITHUB_ENV, a known technique used by the SCKIT supply-chain worm to perform credential harvesting during CI pipeline execution.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.


