Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects phishing attempts leveraging SendGrid infrastructure to send emails that impersonate well-known financial brands. The detection looks for emails with authentication checks passing (SPF/DKIM/DMARC) where the sender domain is suspicious (e.g., .asia or .com not matching the brand) and the volume of such messages suggests an automated campaign.
This rule monitors for two distinct suspicious patterns: first, the interaction between Claude Desktop and the CEF (Chromium Embedded Framework) library, which may indicate unauthorized plugin or extension loading; second, the execution of non-standard binaries initiated by various JetBrains IDE processes located outside of standard program directories, which could indicate process hollowing or unauthorized tool execution.
Detects web proxy requests that resemble phishing attempts targeting Apple Activation Lock. The rule identifies URLs containing specific Apple-related keywords in combination with common phishing URL paths, while filtering out legitimate Apple support documentation pages.
Detects the presence of the i-Realm companion tool associated with the AnonyMousKIT PhaaS platform, which is designed to bypass iOS Activation Lock features.
This rule detects interaction between an internal host and the Vapi.ai API, typically used for automating AI-based voice phishing (vishing) calls. It identifies the initiation of a call via POST requests to the Vapi.ai API and subsequent callbacks from Vapi.ai to an attacker-controlled webhook endpoint used for tracking call status.
Detects artifacts associated with the JWR phishing framework client engine, specifically focusing on the presence of self-referential .toString().search() anti-debugging checks, decoy variable naming conventions, and WebSocket communication components (JWRCID/JWRCVV, ws-worker.js) used for session establishment.
Detects the presence of known AnonyMousKIT Phishing-as-a-Service (PhaaS) shared components (legacy.js, Core.js, ToolsController.php) by matching specific file hashes or detecting these filenames in small files. This rule is designed to identify backend infrastructure used by phishing resellers.
Detects network indicators and session patterns associated with the JWR Phishing Framework, specifically targeting its WebSocket-based command and control (C2) communication, client engine (main.js/ws-worker.js) retrieval, and unique session token (JWRCVV) usage.
Detects the creation or writing of the specific log file '/logs/send_sms_apix.log' associated with the AnonyMousKIT Phishing-as-a-Service (PhaaS) platform. This file is typically used by the kit to record SMS billing or gateway activity during a phishing operation.
This rule detects network connections (TLS SNI and HTTP requests) to domains associated with the AnonyMousKIT PhaaS (Phishing-as-a-Service) platform. It flags connections to known phishing backend domains and monitors for access to suspicious management dashboard paths commonly utilized by this threat actor for managing phishing orders and communications.
Detects incoming emails that use 'Apple' or 'Find My' related strings in the sender display name while originating from common consumer email relay domains like Gmail or iCloud, which is indicative of a social engineering or phishing attempt attempting to impersonate Apple support.
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
Detects DNS queries for domains containing specific brand-related strings (such as government agencies or courier services) coupled with high-risk top-level domains (TLDs). This pattern is frequently used by adversaries to register infrastructure for phishing and social engineering campaigns by mimicking legitimate organizational presence.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.

