Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the execution of MSBuild.exe when spawned by a PowerShell process. This is a common pattern for proxying execution of malicious code, such as the LxBaseRAT, by leveraging MSBuild's inline task capability to execute C# or VB.NET code within a signed Microsoft binary.
Detects the abuse of WerFaultSecure.exe or similar Windows Error Reporting processes, invoked with debugging or dumping flags against security/EDR process names, or spawned by unexpected parent processes. This technique is often used to freeze security tools (EDR-Freeze) by exploiting process suspension via mini-dump handles.
Detects activity associated with the SharePoint ToolShell exploitation chain, specifically monitoring the w3wp.exe process for spawning suspicious child processes like cmd.exe or powershell.exe, and the creation of unexpected .aspx files within the SharePoint LAYOUTS directory.
Detects instances where the Node.js runtime environment (node.exe) deletes a file named 'sharedLoad.min.js' located within a 'node_modules' directory. This behavior is indicative of anti-forensic cleanup activities where malicious npm packages attempt to remove their own footprints or temporary artifacts post-execution.
Detects Xray-core C2 tunnel traffic where the TLS SNI is spoofed to appear as 'dl.google.com'. The detection specifically looks for this behavior originating from non-browser processes such as 'wkspbroker.exe' or 'radcui.dll', which is indicative of malicious tunneling activity.
Detects HTTP and TLS traffic patterns indicative of data exfiltration to Slack, specifically targeting hardcoded Slack API tokens, Slack channel IDs in HTTP request bodies, or traffic directed to hooks.slack.com, commonly associated with malicious npm packages.
Detects HTTP and TLS traffic patterns indicative of data exfiltration to Slack, specifically targeting hardcoded Slack API tokens, Slack channel IDs in HTTP request bodies, or traffic directed to hooks.slack.com, commonly associated with malicious npm packages.
Detects network activity indicating interaction with known Adversary-in-the-Middle (AiTM) phishing infrastructure. This includes direct outbound connections to specific suspicious IP addresses and the identification of proxied Microsoft 365 OAuth authorization flows redirected to non-Microsoft hosts.
Detects the modification of registry keys under HKCU\Software\Classes\CLSID\...\InProcServer32, which is a common method for achieving persistence. The rule flags when these registry keys point to file paths within the local user profile (AppData), which is frequently used by malicious actors to load custom DLLs when the corresponding COM object is initialized.
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
Detects Azure AD sign-in events where the user-agent matches common scripting or automation libraries such as python-requests. This behavior is often indicative of automated token replay attacks, where attackers attempt to leverage stolen session cookies or tokens (e.g., following AiTM phishing) via proxy infrastructure.
Detects the execution and behavioral patterns associated with the malicious 'indexed-btree' npm package. The rule specifically looks for code patterns where a malicious loader is injected into 'BTree.prototype.set' and triggered at runtime. It also monitors for suspicious process spawning behavior, such as running node processes with detached and hidden windows flags, often used by the package to maintain persistence or execute malicious payloads silently.
Detects instances where the AnyDesk process spawns cmd.exe or executes a batch script, which is a common indicator of an attacker performing post-exploitation activities via a remote access session.
Detects the creation of a shortcut file named 'AppUpdateHelper.lnk' within the Windows Startup folder by the 'UpdateAssistant.exe' process. This pattern may indicate an attempt to establish persistence by an application posing as an update process.
Detects the execution of the Windows Workspaces Broker process (wkspbroker.exe) when it loads a library (DLL) from a path within the RemoteApp Gateway directory under LOCALAPPDATA. This behavior is associated with DLL side-loading techniques used to execute malicious payloads such as the Xray-core implant.
Detects network traffic from internal hosts interacting with Ethereum Sepolia testnet contracts via common blockchain infrastructure providers (Alchemy, Infura) or JSON-RPC calls. These patterns are characteristic of 'indexed-btree' malware utilizing decentralized blockchain technology for command-and-control polling.
This rule detects incoming email messages containing .zip attachments with filenames that mimic financial documents (e.g., NFe, DANFE, invoice-related keywords) combined with numerical strings. This naming pattern is commonly associated with phishing campaigns attempting to deliver malicious archives.
Detects a sequence of events where a user's MFA configuration is modified (typically via a help-desk impersonation vishing attack) followed closely by a successful sign-in from a new IP address. This pattern is indicative of attackers hijacking sessions or stealing credentials by coercing victims into resetting MFA settings.
Detects the use of common command-line tools (curl, wget, python, etc.) to interact with known cloud provider metadata service IP addresses or URL paths, often performed by shell processes. This behavior is frequently associated with initial reconnaissance or attempts to steal identity tokens from cloud-based virtual machines.

