Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream (ADS) from files. This stream is responsible for the 'Mark-of-the-Web' (MOTW) which triggers security warnings in Windows, including SmartScreen and Protected View. Adversaries use this technique to evade security controls on downloaded malicious files.
Detects a specific network handshake pattern characterized by the string 'REVERSE_PROXY|' within the first 16 bytes of an established TCP connection, consistent with the x47.c Fast-Flux botnet command and control (C2) communication protocol.
Detects network traffic consistent with the x47.c bot performing a SOCKS5 reverse-proxy handshake to a command-and-control (C2) server. The rule triggers on the specific 'REVERSE_PROXY|' string signature within established outbound TCP connections.
Detects high-frequency outbound network connections to known large language model (LLM) API providers (OpenAI, xAI, Anthropic) originating from a single endpoint within a short timeframe. This activity is indicative of potential API key theft, where an attacker uses a compromised legitimate key to exhaust credit quotas or exfiltrate data via unauthorized API calls, bypassing the intended application.
Detects instances where the suspicious binary 'x47_bot.exe' performs process injection or hollows a process, followed by an attempt to gain or elevate privileges (such as via UAC bypass, token manipulation, or privilege checking) on the same host within a 15-minute window.
Detects non-browser processes accessing sensitive browser-stored credential and cookie databases concurrently with access to Discord local storage, which is a common behavior of information-stealing malware (e.g., x47.c) to aggregate credentials for exfiltration.
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
Detects bursts of AI-paraphrased, brand/executive-impersonating email lures delivered to the inbox: clusters near-duplicate subject-line variants from the same sending domain within a 6-hour window, and requires a corroborating signal (authentication failure or a sender domain first seen within the last 14 days) plus an ESP allow-list exclusion to avoid flagging legitimate bulk/newsletter mail. Maps to T1683 (Generate Content) as the downstream-delivery proxy for AI-generated lure content.
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
Detects instances where msbuild.exe is spawned from suspicious parent processes without valid project files and subsequently receives cross-process injection activity (such as CreateRemoteThread or WriteProcessMemory) within a short timeframe. This behavior is indicative of an adversary attempting to use MSBuild to proxy malicious code execution.
Detects instances where msbuild.exe is spawned from suspicious parent processes without valid project files and subsequently receives cross-process injection activity (such as CreateRemoteThread or WriteProcessMemory) within a short timeframe. This behavior is indicative of an adversary attempting to use MSBuild to proxy malicious code execution.
Detects the creation or modification of registry run keys under HKCU or HKEY_USERS that use the value 'WindowsDefender' to point to an executable located within the AppData directory. This is a common technique used by malware to establish persistence while masquerading as a legitimate security component.
Detects the creation or modification of registry run keys under HKCU or HKEY_USERS that use the value 'WindowsDefender' to point to an executable located within the AppData directory. This is a common technique used by malware to establish persistence while masquerading as a legitimate security component.
Detects instances where msbuild.exe is spawned from suspicious parent processes without valid project files and subsequently receives cross-process injection activity (such as CreateRemoteThread or WriteProcessMemory) within a short timeframe. This behavior is indicative of an adversary attempting to use MSBuild to proxy malicious code execution.
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.


