Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the installation and execution of Cloudflare Tunnel (cloudflared.exe) as a Windows service. Adversaries may abuse this utility to create unauthorized persistent network tunnels, enabling covert remote access to the internal network. This rule correlates process creation events involving 'service install' or 'tunnel run' commands with Windows service installation events referencing the cloudflared binary.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
Detects high-privileged Entra ID accounts successfully reaching the verification stage of the Self-Service Password Reset (SSPR) process. While SSPR is automatically enabled for administrative accounts, this activity is anomalous and potentially indicates an attacker focusing on discovered privileged accounts after performing broader enumeration.
Detects anomalous, high-volume account enumeration against the Microsoft Self-Service Password Reset (SSPR) endpoint from a single source IP. The rule identifies a pattern of mixed response codes, specifically interleaving '50034' (Account does not exist) with successful or other outcomes, which indicates the use of automated tools to validate the existence of corporate accounts via response differentiation.
Detects anomalous, high-volume account enumeration against the Microsoft Self-Service Password Reset (SSPR) endpoint from a single source IP. The rule identifies a pattern of mixed response codes, specifically interleaving '50034' (Account does not exist) with successful or other outcomes, which indicates the use of automated tools to validate the existence of corporate accounts via response differentiation.
Detects anomalous Agentforce session activity where a user, via the General CRM subagent, queries Lead records followed shortly by an access request to Account records. This pattern is indicative of a potentially hijacked agent session attempting to pivot from lead review into unauthorized data access of broader customer information.
This rule detects Salesforce Agentforce or similar AI-driven chat responses that contain external URLs with non-standard Top-Level Domains (TLDs). It identifies cases where the organization's redactor failed to strip a URL due to unexpected TLDs or unusual trailing termination characters (e.g., brackets) that are still rendered as clickable links in the interface. Such links may facilitate phishing, credential harvesting, or redirection to malicious sites.
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
Detects the execution of Node.js or Python interpreters from user-writable directories (AppData/Local) that are executing specific script files. This pattern is indicative of potential malicious activity where legitimate scripting languages are leveraged to run unauthorized payloads dropped into the user profile.
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
Detects the use of reg.exe to query the MachineGuid value from the Windows Registry (HKLM\SOFTWARE\Microsoft\Cryptography). This behavior is often associated with adversary reconnaissance, specifically host fingerprinting, to uniquely identify compromised machines.
Detects unauthorized or non-standard processes attempting to access sensitive browser cookie storage files, which is a common technique used by credential-stealing malware to exfiltrate session data and bypass multi-factor authentication.
Detects the use of 7-Zip (7z.exe) to extract a file named drata.dat using command line arguments that indicate silent extraction from an encrypted or password-protected archive. This behavior is associated with the LegionLoader malware, which uses this technique to stage its payload.
This rule detects suspicious PowerShell activity associated with the Lightlife RAT, specifically targeting Google Chrome's login data files to steal credentials and performing checks for the presence of cryptocurrency wallets.
This rule detects when a user or service account accesses or downloads a high volume of files from SharePoint or OneDrive that match sensitive keywords such as 'password', 'secret', 'credential', or specific file extensions like '.pem', '.pfx', and '.env'. This behavior is indicative of an attempt to harvest credentials, API keys, or configuration secrets from cloud storage repositories.


