Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects the installation of browser extensions that request highly sensitive, over-broad permissions such as proxy configuration management and web authentication provider access, combined with full host access (<all_urls>). This pattern is often indicative of malicious extensions masquerading as legitimate tools (e.g., VPNs) to facilitate credential theft or traffic interception.
Detects the first-seen external Remote Desktop Protocol (RDP) logon event for a specific user and network provider (ASN) within the last 24 hours, compared against a 14-day historical baseline. This can indicate initial access via compromised credentials or RDP exploitation.
Detects PowerShell processes invoked with obfuscated command lines that enumerate Microsoft.PowerShell.Utility
exported commands and invoke cmdlets indirectly by array index. This technique is used to evade
detections that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.
exported commands and invoke cmdlets indirectly by array index. This technique is used to evade
detections that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.
Detects instances where Windows Terminal (wt.exe) is used to spawn PowerShell or pwsh as a child process. This pattern may be indicative of ClickFix-style social engineering attacks where users are deceived into pasting or executing malicious commands within a terminal environment.
The following analytic detects the loading of known vulnerable Windows drivers, which may indicate potential persistence or privilege escalation attempts. It leverages Windows System service install EventCode 7045 to identify driver loading events and cross-references them with a list of vulnerable drivers. This activity is significant as attackers often exploit vulnerable drivers to gain elevated privileges or maintain persistence on a system. If confirmed malicious, this could allow attackers to execute arbitrary code with high privileges, leading to further system compromise and potential data exfiltration. This detection is a Windows Event Log adaptation of the Sysmon driver loaded detection written by Michael Haag.
This rule detects modifications to the 'HideExclusionsFromLocalAdmins' registry key within the Windows Defender policy configuration. An adversary may modify this key to hide configured security exclusions from local administrators, facilitating defense evasion. The rule specifically looks for non-system process attempts to modify this key, contrasting against expected legitimate updates performed by 'gpsvc' (Group Policy Service).
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
This rule detects network communication, DNS queries, email interactions, and URL clicks associated with known TA419 threat actor infrastructure. It monitors multiple telemetry sources to identify indicators of compromise (IOCs) such as specific domains, IP addresses, and email addresses.
This rule detects network communication, DNS queries, email interactions, and URL clicks associated with known TA419 threat actor infrastructure. It monitors multiple telemetry sources to identify indicators of compromise (IOCs) such as specific domains, IP addresses, and email addresses.
Detects command-line activity indicative of attempts to dump LSASS memory after performing in-memory unhooking or bypassing of security monitoring DLLs (ntdll.dll, amsi.dll, win32kbase.sys). This behavior is characteristic of adversaries attempting to harvest credentials while evading EDR/AV visibility.
Detects the GOST tunnel binary deployed as svchost.exe from a staging directory, identified by its known hash, or by an unsigned PE importing config.dll with a matching MZ header and embedded config.dll reference (reduces FPs from legitimately signed software that imports a DLL of the same name)
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
Detects a suspected ClickFix social engineering attack where a user is tricked into pasting malicious commands into Windows Terminal, leading to a PowerShell download, followed by the appearance of specific known malicious artifacts (LockScreenContentServer.exe, dui70.dll, or 1.bat) within 15 minutes on the same device.
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
This rule detects the presence of specific SHA-256 file hashes associated with the 'VPN for X' malicious proxy extension family, which are known to be used to transform systems into nodes within a proxy network.
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
Unsigned LDAP Bind
Cortex XDR
Detects Lightweight Directory Access Protocol (LDAP) binds that are performed without signing or encryption. Attack tools such as NetExec, ldapdomaindump, and Impacket frequently use simple, unencrypted LDAP binds over port 389, which can result in the transmission of credentials in cleartext. This rule monitors Windows Event ID 2889 on Domain Controllers, which logs cleartext LDAP bind attempts.
The following analytic identifies a local successful authentication event on a Windows endpoint using the Kerberos package.
It detects EventCode 4624 with LogonType 3 and source address 127.0.0.1, indicating a login to the built-in local Administrator account.
This activity is significant as it may suggest a Kerberos relay attack, a method attackers use to escalate privileges.
If confirmed malicious, this could allow an attacker to gain unauthorized access to sensitive systems, execute arbitrary code, or create new accounts in Active Directory, leading to potential system compromise.
It detects EventCode 4624 with LogonType 3 and source address 127.0.0.1, indicating a login to the built-in local Administrator account.
This activity is significant as it may suggest a Kerberos relay attack, a method attackers use to escalate privileges.
If confirmed malicious, this could allow an attacker to gain unauthorized access to sensitive systems, execute arbitrary code, or create new accounts in Active Directory, leading to potential system compromise.
Page 3 of 1866





