Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potential malicious activity by monitoring for known malicious file hashes (MD5) across file and process events, and correlating them with known Command and Control (C2) infrastructure communication patterns, including specific IP addresses and URI paths.
This rule detects potential malicious activity by monitoring for known malicious file hashes (MD5) across file and process events, and correlating them with known Command and Control (C2) infrastructure communication patterns, including specific IP addresses and URI paths.
This rule detects potential malicious activity by monitoring for known malicious file hashes (MD5) across file and process events, and correlating them with known Command and Control (C2) infrastructure communication patterns, including specific IP addresses and URI paths.
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
Detects the execution of AutoIt-related processes from temporary directories that are attempting to load or execute suspicious .ini configuration files or specifically named executables, which is a common delivery mechanism for malware such as AsyncRAT.
This rule detects potential persistence mechanisms where a suspicious batch file (.bat) is placed within the Windows Startup folder and subsequently executed using command-line arguments that include specific file extensions like .exe and .ini. This behavior is indicative of malware, such as remote access trojans (RATs), attempting to maintain persistence upon system reboot.
Detects process execution patterns consistent with the "ClickFix" social
engineering technique, where a user is lured (via a fake CAPTCHA, browser
error, or "verify you are human" page) into pressing Win+R, pasting a
pre-copied malicious command, and pressing Enter. This typically launches
PowerShell, mshta, cmd, or curl directly as a child of explorer.exe with
no legitimate parent chain (no browser, no script host), often with
obfuscated or encoded command lines, and frequently reaching out to
attacker infrastructure.
engineering technique, where a user is lured (via a fake CAPTCHA, browser
error, or "verify you are human" page) into pressing Win+R, pasting a
pre-copied malicious command, and pressing Enter. This typically launches
PowerShell, mshta, cmd, or curl directly as a child of explorer.exe with
no legitimate parent chain (no browser, no script host), often with
obfuscated or encoded command lines, and frequently reaching out to
attacker infrastructure.
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
Detects outbound network connections to known command-and-control IP addresses associated with the SpiceRAT malware family. The rule monitors DeviceNetworkEvents for successful connections or connection attempts over ports 80 and 443.
Page 280 of 1871



