Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates execution of common command-line utilities or scripting interpreters, such as cmd.exe, powershell.exe, or certutil.exe. This behavior is highly atypical for web servers and is often indicative of exploitation attempts or post-exploitation activities following an initial compromise of a web application.
This rule detects potential web shell activity on Microsoft Exchange servers by identifying suspicious processes (like cmd.exe, powershell.exe) spawned by w3wp.exe (IIS worker process) that are associated with the creation or modification of common web shell file extensions (.aspx, .ashx, .asax) within critical Exchange server directories.
Detects high-frequency execution of Python interpreter processes within a short timeframe (40+ distinct command lines in 15 minutes). This behavioral pattern is indicative of automated or autonomous agent-driven payload delivery and execution, as seen in JADEPUFFER and ENCFORGE campaigns.
This rule detects processes accessing or files being interacted with that are known to contain sensitive information, including API keys, credential files, database configurations, and cryptocurrency wallets. It monitors command-line activity for utilities like python, bash, and grep interacting with sensitive strings, and tracks file system access to sensitive paths.
This rule detects attempts to exploit Apache Nacos vulnerabilities, including authentication bypass and unauthorized administrative account creation. It monitors process executions of common tools (like curl and java) and network connections targeting known Nacos service ports (8848, 9848) containing indicators of exploit patterns such as login bypass endpoints or SQL injection sequences targeting the user table.
Detects the use of ScreenConnect client processes initiating rapid outbound network connections to multiple distinct devices within a short timeframe (1 hour). This behavior is often indicative of unauthorized lateral movement, automated discovery, or mass-deployment of remote access sessions using legitimate administrative software.
Detects a sequence of activity involving the use of the MySQL 'AES_ENCRYPT' function followed by a 'DROP TABLE', 'DROP SCHEMA', or 'DROP DATABASE' command on the same host within a 30-minute window. This behavior is consistent with extortion tactics, such as the JADEPUFFER campaign, where attackers encrypt sensitive database records and delete the original tables to compel ransom payments.
Detects potential DCSync attacks by monitoring Windows Security Event ID 4662 for specific Directory Service Replication GUIDs. The rule identifies attempts by unauthorized principals (not domain controllers) to request replication data from the Active Directory domain controller, which is a key indicator of credential harvesting using tools like Mimikatz.
Detects potential web shell or malicious DLL deployment into Microsoft Exchange or IIS directories by the IIS worker process (w3wp.exe), as well as suspicious child process execution (such as command-line shells or credential discovery tools) spawned directly from IIS worker processes.
Detects the ScreenConnect remote access binary spawning suspicious child processes often associated with lateral movement, system reconnaissance, or anti-forensics activity (such as deleting shadow copies, modifying boot configuration, or using administrative tools for remote command execution). This behavior is highly indicative of an adversary abusing legitimate RMM software to execute post-exploitation commands.
Detects the presence of natural-language self-narration in code comments within Python or SQL scripts. This pattern is indicative of LLM-driven agentic execution, where automated agents narrate their own malicious actions, such as enumeration, data exfiltration, or database manipulation, as observed in the JADEPUFFER campaign.
Detects the execution of 'SimpleService.exe' when the binary is located within a restricted subdirectory associated with JWrapper-Remote Access. This pattern may indicate the execution of unauthorized or restricted remote access tools.
Detects the addition of a user to the 'Domain Admins' group using common administrative command-line tools such as net group, Add-ADGroupMember, dsadd, or net localgroup. This serves as a proxy indicator for potential privilege escalation.
Detects the execution of MySQL process command lines that simultaneously contain the strings 'AES_ENCRYPT' and 'UPDATE'. This pattern often indicates attempts to manipulate data within the database via SQL injection or unauthorized database modification.
Detects the ENCFORGE locker malware, associated with the JADEPUFFER campaign, which specifically targets AI/ML-related files such as model checkpoints, vector databases, and training data for the purpose of malicious encryption or destruction.
Detects instances where a Langflow process spawns a Python process using command-line arguments involving base64 decoding or character-based execution, which is often indicative of malicious code injection or shellcode execution.
Detects file creation events initiated by ScreenConnect (ConnectWise Control) client processes. ScreenConnect is a legitimate remote support and RMM tool often leveraged by adversaries for remote access or as a secondary persistence mechanism. Monitoring file creation by these processes may indicate the installation of additional tools, scripts, or malware via a remote support session.
Detects the use of native Windows utilities (vssadmin, wbadmin, bcdedit, wmic) to delete volume shadow copies, backup catalogs, or disable system recovery features. This behavior is a common precursor to or component of ransomware encryption operations intended to prevent system recovery.
Detects the execution of common command-line or scripting interpreters (cmd, powershell, cscript, etc.) spawned by the ScreenConnect remote administration client. This is a common pattern used by attackers leveraging legitimate remote access tools for post-exploitation activities and lateral movement.
Detects the presence of known malicious RubyGems package names and Cross-Site Scripting (XSS) payloads within process commands, file paths, or network URLs, indicative of an attempt to target repository registries or administrative interfaces with supply chain injection attacks.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Page 279 of 1871


