Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of Evil-WinRM or WinRM-fs command-line utilities combined with network connections over the WinRM ports (TCP 5985/5986). This activity is indicative of remote administrative tools being used for potential lateral movement or agent delivery, specifically observed in the context of the Toy Ghouls threat activity involving the Bird Agent.
Detects unauthorized directory replication requests (DRSGetNCChanges or DRSReplicaSync) originating from a host that is not identified as a Domain Controller. This behavior is indicative of a DCSync attack, where an adversary impersonates a domain controller to extract credential hashes from the Active Directory database.
Detects suspicious process execution spawned by ScreenConnect client processes, which may indicate abuse of remote access sessions for arbitrary command execution. This includes both direct child processes of ScreenConnect client binaries and execution of binaries staged within known ScreenConnect working and temporary directories.
Detects the execution of Mimikatz or the use of specific Mimikatz command-line arguments intended to extract credentials from LSASS memory, a common technique for credential harvesting during post-exploitation activities.
Detects anomalous process execution (cmd.exe or powershell.exe) initiated by PaperCut application server processes (pc-app.exe or java.exe), followed immediately by the modification of the 'Domain Admins' group membership. This behavior is indicative of potential post-exploitation privilege escalation activity following a successful PaperCut authentication bypass.
The following analytic correlates modifications to the Windows RunMRU registry key with clipboard content
changes initiated by browsers. It aims to detect ClickFix scenarios in which commands copied
from a browser are subsequently executed on the Windows system through the Run dialog box.
changes initiated by browsers. It aims to detect ClickFix scenarios in which commands copied
from a browser are subsequently executed on the Windows system through the Run dialog box.
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
Detects the use of tasklist.exe combined with process filtering (findstr) to identify common debugger names such as 'dbg.exe', 'x64dbg.exe', 'windbg.exe', or 'ollydbg.exe'. This technique is a known evasion tactic employed by the Kimsuky threat group (and others) to check for the presence of analysis tools before continuing execution of malicious batch scripts.
Detects the creation of a scheduled task named 'OneDrive KeepAlive' or a task set to execute every 5 minutes, in conjunction with the execution of 'taskhostw.exe' containing 'exec hide' in its command line. This pattern is indicative of the Kimsuky threat group using a renamed version of the NirCmd utility to maintain persistence and execute commands silently.
Detects the suspicious copying of the Windows certutil.exe binary to an alternate location (e.g., /Users/Public/Downloads/) followed by execution with decoding or caching flags. This behavior is indicative of an adversary attempting to use certutil as a LOLBin to decode or reassemble malicious payloads, a tactic frequently observed in Kimsuky-related LNK malware campaigns.
Detects unauthorized access to common browser credential and cookie files by processes other than standard web browsers. This activity is a common indicator of credential harvesting malware or unauthorized data collection.
Detects PowerShell command execution containing specific strings associated with the Veil framework XOR decoding routine, including a hardcoded key and the use of the -bxor operator for payload deobfuscation.
Detects instances where WScript.exe or CScript.exe spawn PowerShell.exe as a child process. The rule specifically looks for command-line arguments indicative of policy bypass (-ExecutionPolicy Bypass) and remote payload retrieval (Invoke-WebRequest, DownloadString), which is a common pattern in obfuscated JavaScript-based infection chains.
Detects the use of .NET reflection APIs (specifically System.Reflection.Assembly::Load) within PowerShell script blocks. This technique allows for the dynamic loading of .NET assemblies into memory, often to execute obfuscated or encrypted payloads without writing them to disk, which is a common tactic for bypassing file-based security controls.
Detects the use of PowerShell Stop-Process being used to terminate common scripting and .NET-related processes, a behavior associated with the Veil#Drop loader to clear potential conflicts or interference from legitimate host processes.
Detects the use of [ScriptBlock]::Create() within PowerShell command lines. This method allows for the dynamic construction and execution of arbitrary PowerShell code entirely in memory, a technique often used by fileless malware and frameworks like Veil#Drop to evade disk-based detection mechanisms.
Detects the potential creation or execution of malicious JavaScript files that masquerade as PDF or other common documents using double extensions (e.g., .pdf.js). This behavior is often associated with file-based loaders where the operating system masks the true file extension. The rule also triggers when these files are explicitly launched via Windows Script Host (wscript.exe or cscript.exe).
This rule aggregates vulnerability data from Microsoft Defender for Endpoint (Threat and Vulnerability Management) over the last 7 days. It groups vulnerable devices by CVE ID and severity level, providing an overview of known software weaknesses currently present across the fleet.
Detects the presence of a specific malicious _socket.pyd Python module associated with LegionLoader dropped into non-standard directories like 'Traiolx Custom Utils'. The detection leverages file path patterns and known file hashes of the malicious component.
Page 282 of 1871


