Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects network connections to known remote tunneling and relay services (e.g., ngrok, Cloudflare Tunnel) initiated by commonly abused LOLBins or processes running from user-writable directories. This behavior is often indicative of an adversary establishing persistent remote access or egress channels for command-and-control communication.
Detects potential DLL side-loading attempts involving GlobalProtect VPN components. The rule identifies the execution of GlobalProtect.exe with specific command-line arguments combined with the presence of suspicious versions of bcrypt.dll or WININET.dll within the same directory, which are characteristic of recent malicious activity involving modified DLL files targeting GlobalProtect environments.
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
Detects the execution of the Rubeus.exe utility with command-line arguments indicative of Kerberos-related credential harvesting and abuse, such as Kerberoasting, AS-REP Roasting, and Pass-the-Ticket attacks.
This rule monitors for a multi-stage attack pattern involving two potential indicators: first, it identifies phishing emails containing a 'Google Docs' link combined with an attachment named 'API Logic Flaw'. Second, it detects browser activity involving the paste of JavaScript code or suspicious browser clipboard activity, which may indicate an attacker attempting to execute malicious scripts directly in the user's browser context.
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
Detects rapid AI agent state transitions (from 'think' to 'act') within Microsoft Edge processes, specifically identifying potential exploitation of the CVE-2026-55945 race condition vulnerability, which could be used to force the unauthorized execution of an injected prompt.
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
BigBear 2.0 IOC HUNT (Cortex XDR)
Cortex XDR
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
Detects instances where a non-administrative user account creates two or more computer accounts within a 24-hour window. This behavior can be indicative of a compromised account attempting to add rogue machines to the domain for persistence or further lateral movement.
Detects unauthorized access or decryption attempts related to Group Policy Preferences (GPP) files stored in the SYSVOL share. Attackers often target these files to retrieve credentials stored in the 'cpassword' attribute, which can be decrypted using publicly known keys.
Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
Detects potential credential dumping activities by monitoring process executions associated with known tools (Mimikatz, Procdump, Gsecdump) or commands that interact with the LSASS process memory to extract secrets.
Page 291 of 1871




