Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule hunts for indicators associated with the TrustSink technique, which involves using rogue External Authentication Methods (EAM) or malicious OIDC providers to bypass authentication or maintain persistence within a cloud environment. It monitors Azure AD sign-in and audit logs, alongside DNS and network events, for references to known malicious domains and URLs used for EAM-based attacks.
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
This rule monitors for successful sign-in events that follow a threshold of failed authentication attempts within a one-hour window, specifically flagging cases where the successful login originated from a new location or a previously unseen device, which is often indicative of successful brute force or password spraying attacks.
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
Detects indicators associated with the exploitation of CVE-2025-3248 in Langflow. The rule identifies anomalous web requests targeting the /api/v1/validate/code endpoint, subsequent suspicious process creation (base64 encoded payloads in Python/shell), and network communication with identified command and control (C2) or data exfiltration IP addresses. It also includes alerts for observed contact with known extortion email addresses.
Detects indicators associated with the exploitation of CVE-2025-3248 in Langflow. The rule identifies anomalous web requests targeting the /api/v1/validate/code endpoint, subsequent suspicious process creation (base64 encoded payloads in Python/shell), and network communication with identified command and control (C2) or data exfiltration IP addresses. It also includes alerts for observed contact with known extortion email addresses.
The following analytic detects the installation of the XMRIG coinminer driver on a system. It identifies the loading of the `WinRing0x64.sys` driver, commonly associated with XMRIG, by analyzing Sysmon EventCode 6 logs for specific signatures and image loads. This activity is significant because XMRIG is an open-source CPU miner frequently exploited by adversaries to mine cryptocurrency illicitly. If confirmed malicious, this activity could lead to unauthorized resource consumption, degraded system performance, and potential financial loss due to unauthorized cryptocurrency mining.
The following analytic identifies user accounts experiencing more than 5 account lockouts within a 5-minute time window.
It leverages the 'Change' data model and groups account lockout events into 5-minute time buckets to identify a high frequency of lockouts associated with the same user and destination.
This activity may indicate password spraying, brute-force activity, or repeated authentication attempts using invalid or outdated credentials.
If confirmed malicious, this behavior may indicate an attempt to gain unauthorized access to user accounts and could precede further compromise or lateral movement within the environment.
It leverages the 'Change' data model and groups account lockout events into 5-minute time buckets to identify a high frequency of lockouts associated with the same user and destination.
This activity may indicate password spraying, brute-force activity, or repeated authentication attempts using invalid or outdated credentials.
If confirmed malicious, this behavior may indicate an attempt to gain unauthorized access to user accounts and could precede further compromise or lateral movement within the environment.
This rule detects network traffic containing specific API paths or hardcoded tokens known to be associated with suspicious or malicious activity, potentially indicating command-and-control (C2) communication or unauthorized interaction with a web service.
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
Detects instances where the legitimate Windows Character Map utility (charmap.exe) is spawned by suspicious processes or PowerShell, and subsequently loads clr.dll. This behavior is indicative of potential DLL sideloading or process injection techniques used by malware to execute arbitrary code within a trusted system process context.
This rule monitors for indicators of compromise (IOCs) associated with the ShinyHunters threat actor, including specific malicious domains, IP addresses, and artifacts found in command lines or event data. It aggregates telemetry from network events, Entra ID sign-in logs, cloud application activity, email logs, process execution, and general device events to detect interaction with known malicious infrastructure or execution of threat-actor specific artifacts.
This rule detects a password-spraying attack pattern directed at privileged or manager-titled accounts. It monitors for multiple failed sign-in attempts from a single source IP address against a large volume of distinct user accounts identified as managers or senior staff. The detection logic filters for low-frequency attempts per account, which is indicative of a distributed spray attack designed to evade account lockout thresholds while focusing on high-value targets.
This rule detects a password-spraying attack pattern directed at privileged or manager-titled accounts. It monitors for multiple failed sign-in attempts from a single source IP address against a large volume of distinct user accounts identified as managers or senior staff. The detection logic filters for low-frequency attempts per account, which is indicative of a distributed spray attack designed to evade account lockout thresholds while focusing on high-value targets.
This rule detects a password-spraying attack pattern directed at privileged or manager-titled accounts. It monitors for multiple failed sign-in attempts from a single source IP address against a large volume of distinct user accounts identified as managers or senior staff. The detection logic filters for low-frequency attempts per account, which is indicative of a distributed spray attack designed to evade account lockout thresholds while focusing on high-value targets.
Detects successful authentication events for accounts that have been dormant for at least 90 days, correlated with suspicious activity markers such as recent failed sign-in attempts, access from an unfamiliar geographic location or ASN, or a complete absence of historical sign-in activity.
Detects successful authentication events for accounts that have been dormant for at least 90 days, correlated with suspicious activity markers such as recent failed sign-in attempts, access from an unfamiliar geographic location or ASN, or a complete absence of historical sign-in activity.
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.




