Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects outbound TLS traffic to the domain 'trace-flow.ru', which is associated with Max Messenger covert telemetry beaconing behavior. The rule inspects the Server Name Indication (SNI) field in the TLS handshake for the specific domain string.
Detects high-frequency outbound TLS connections to 'api-gost.oneme.ru', which is indicative of potential bulk contact list uploading, possibly related to unauthorized data collection by the Max Messenger application.
Detects rapid termination of specific mobile messenger applications (Max) within seconds of starting, while indicators of the Frida dynamic instrumentation tool are concurrently detected on the device. This pattern suggests the application is identifying the presence of a hooking/instrumentation environment and self-terminating as a defense mechanism. The detection is further correlated with failed connection attempts to the application's backend.
Detects rapid termination of specific mobile messenger applications (Max) within seconds of starting, while indicators of the Frida dynamic instrumentation tool are concurrently detected on the device. This pattern suggests the application is identifying the presence of a hooking/instrumentation environment and self-terminating as a defense mechanism. The detection is further correlated with failed connection attempts to the application's backend.
Detects rapid termination of specific mobile messenger applications (Max) within seconds of starting, while indicators of the Frida dynamic instrumentation tool are concurrently detected on the device. This pattern suggests the application is identifying the presence of a hooking/instrumentation environment and self-terminating as a defense mechanism. The detection is further correlated with failed connection attempts to the application's backend.
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
Detects potentially malicious script execution chains where a user launches a JavaScript file (.js/.jse) from commonly abused directories (Downloads, Documents, Desktop, AppData, WinRAR temporary folders) via wscript.exe, which subsequently spawns PowerShell and establishes an external network connection within a short time window. This behavior is commonly associated with malware loaders, phishing attachments, and initial access payloads.
Detects the presence of a specific Russian-language error string ("Не удалось сгенерировать HWID") within binary files, which is characteristic of the HWID generation mechanism used by Vidar Stealer malware.
Detects the spawning of command-line interfaces such as cmd.exe, powershell.exe, or pwsh.exe as child processes of the SharePoint web application worker process (w3wp.exe). This behavior is highly irregular for a web server process and is indicative of potential exploitation, such as remote code execution (RCE) via web application vulnerabilities.
This rule detects malicious deserialization attempts targeting Microsoft SharePoint, specifically leveraging System.Data.Services.Internal.ExpandedWrapper combined with LosFormatter and System.Xaml.XamlServices. This signature is indicative of exploitation attempts related to CVE-2026-65660, allowing an attacker to achieve remote code execution by bypassing SafeControls restrictions.
Detects potential malicious PowerShell activity involving suspicious file paths in 'C:\Users\Public\' and the use of 'UPLOAD' command strings, which may indicate the staging and execution of payloads.
Detects network connections from workstation subnets to domain controllers using administrative protocols such as SMB (445), RPC (135), RDP (3389), or WinRM (5985/5986). This activity is indicative of lateral movement attempts by an adversary attempting to reach critical infrastructure from a compromised workstation in a flat or poorly segmented environment.
Detects an exploitation attempt against the SharePoint WebPartPagesWebService using the GetWebPartPageConnectionInfo method. The rule monitors for suspicious input patterns such as 'Register' and 'ignoreParentFrozen' within the URI query, which are indicative of a directive injection vulnerability.
Detects large and sustained outbound TCP data transfers to external networks, which may indicate mass data exfiltration. The rule monitors established sessions and uses a threshold to identify unusual outbound traffic volume over an extended period.
Detects unauthorized modifications to the Entra ID authentication methods policy or suspicious application activity often associated with the staging of rogue External Authentication Methods (EAM). Adversaries may exploit these configuration changes to intercept or bypass multi-factor authentication (MFA) during user login processes.
Detects network activity associated with a VBScript-based dropper attempting to retrieve payloads from known malicious infrastructure (cdn.imageurlgenerator.com) or abusing legitimate file hosting services (filemail.com) to bypass traditional security filters.
Detects the modification or creation of Azure AD applications that include specific malicious redirect URIs associated with 'TrustSink' style attacks, which abuse external authentication callback mechanisms to intercept tokens and bypass MFA.
Detects an attempt to exploit a quote-injection vulnerability within the SharePoint ToolPane.aspx page, specifically targeting the Register directive to bypass SafeControls restrictions. This pattern is commonly used for remote code execution or unauthorized application behavior modifications by manipulating server-side parsing.



