Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects sign-in activity where an attacker or user fails a phishing-resistant MFA challenge (such as FIDO2, Windows Hello, or Passwordless Phone) and immediately succeeds using a lower-assurance, phishable factor (SMS, Voice call, or Push notification). This pattern is indicative of an Adversary-in-the-Middle (AiTM) attack attempting to bypass stronger authentication methods.
Detects a suspicious authentication pattern involving 3 or more MFA failures within 15 minutes, immediately followed by an MFA success for the same user. This pattern is characteristic of potential Adversary-in-the-Middle (AiTM) activity, where an attacker intercepts a session or MFA token and relays it through separate infrastructure, while the legitimate user's own MFA attempts fail or time out.
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.

