Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
Detects network connection events initiated by known beaconing-related process names. These processes are associated with command and control infrastructure or pivot nodes often used by adversaries for post-compromise activity.
Detects Node.js processes executing suspicious command lines that involve fetching and executing remote JavaScript code. This behavior is indicative of a loader or downloader script commonly used to pull and evaluate malicious payloads at runtime, specifically referencing indicators associated with 'GHAPPIER'.
Detects network beaconing activity from suspicious processes that masquerade as macOS system services, specifically filtered to only trigger when an active Cursor IDE session is detected on the host. This behavior correlates network-based C2 activity with an active development environment, potentially indicating an adversary using legitimate IDE sessions to blend in or exfiltrate development-related data.
KQL Query from file: Rapid bash + Terminal.app burst indicating bulk macOS TCC consent sequence
Detects the reuse of session tokens from distinct network locations, devices, or user agents shortly after a successful MFA-protected login. This behavioral pattern is a primary indicator of Adversary-in-the-Middle (AiTM) phishing, where attackers capture session tokens via reverse proxy to bypass authentication controls.
Detects when a namespace-scoped identity creates, updates, or patches AWS or Azure IAM-related custom resources in Kubernetes. This pattern monitors for a 'confused deputy' scenario where a user might attempt to leverage high-privilege cloud operators (like ACK or ASO v2) that operate with a shared high-privilege identity to modify cloud IAM configurations.
Detects unauthorized or suspicious use of Google Cloud Config Connector (KCC) service accounts to apply high-privilege IAM roles ('roles/owner' or 'roles/resourcemanager.organizationAdmin') at the Organization or Folder scope. This rule monitors for 'SetIamPolicy' API calls where the principal is identified as a KCC-related service account, flagging potential exploitation of KCC's authority to grant excessive permissions.
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
Detects the use of the ntdsutil.exe utility to create an Install From Media (IFM) backup. This technique is often used by adversaries to create a copy of the Active Directory database (NTDS.dit) for offline credential extraction.
Detects the installation and execution of Cloudflare Tunnel (cloudflared.exe) as a Windows service. Adversaries may abuse this utility to create unauthorized persistent network tunnels, enabling covert remote access to the internal network. This rule correlates process creation events involving 'service install' or 'tunnel run' commands with Windows service installation events referencing the cloudflared binary.



