Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects the creation of executable files (.exe, .dll, .ps1) in common writable and potentially transient directories such as Temp, AppData, ProgramData, or Users\Public. It further correlates these file events with process creation events using the file hash to identify instances where such files are subsequently executed.
Detects the execution of wmic.exe, powershell.exe, or pwsh.exe with command-line arguments related to querying antivirus products or security centers (e.g., AntiVirusProduct, SecurityCenter2). The rule focuses on executions originating from non-standard system paths (e.g., Temp, Users, AppData) or processes that lack a valid code signing signature, which is often indicative of reconnaissance by malicious actors.
This rule identifies the execution of specific binaries (Kingsoft Office suite and Onkey/Tendyron components) from suspicious or uncommon directories such as temporary folders, user downloads, or public directories, which may indicate the staging and execution of malicious payloads masquerading as legitimate software.
Detects several potentially malicious activities related to Active Directory Certificate Services (AD CS). This includes high volumes of failed requests (potential enumeration), requests for sensitive templates (privilege escalation), and potential impersonation attempts using Subject Alternative Names (SANs). These activities are associated with AD CS abuse techniques.
Detects instances where the Windows Remote Management host process (wsmprovhost.exe) is associated with the execution of specific suspicious files (config.toml, cplsupport.exe, or wtass.exe) within a short time window. This activity often indicates post-exploitation behavior or remote execution of secondary tools using WinRM.
Detects msiexec.exe executing from the Temp directory with suspicious command-line arguments (such as hidden windows) and spawning child processes like cmd.exe, tasklist.exe, or taskkill.exe. This behavior is often indicative of malicious installation scripts attempting to perform discovery or terminate security processes while remaining stealthy.
This rule monitors for network connections to known command-and-control (C2) IP addresses and the execution or presence of files matching known hashes associated with the 'PhantomC2' threat group or malware family. It correlates data from DeviceNetworkEvents, DeviceFileEvents, and DeviceProcessEvents to identify potential compromise.
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
Detects network communication with identified C2 infrastructure associated with VectraRAT, Amadey, and ClickFix campaigns, as well as the presence of a specific 'callback.json' artifact in temporary directories, which is commonly used for C2 address overrides.
Detects network communication with identified C2 infrastructure associated with VectraRAT, Amadey, and ClickFix campaigns, as well as the presence of a specific 'callback.json' artifact in temporary directories, which is commonly used for C2 address overrides.
Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.
Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
Detects the BlueMoon exploit kit's post-exploitation activity, specifically identifying when a Chromium-based browser process (chrome.exe or msedge.exe) initiates command-line tools such as cmd.exe, powershell.exe, or curl.exe to download and execute a secondary payload named 'msgbox.exe' within the user's temporary directory.
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
Page 292 of 1871



