Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
Detects the stopping or modification of critical security and backup services on Windows endpoints. This behavior often indicates an attempt by an adversary to impair defensive capabilities or disable logging to facilitate malicious activity.
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
Detects network traffic involving TLS certificates or Server Name Indication (SNI) values that attempt to impersonate the Uzbekistan state railway authority (azure.uzrailwaystax.com). The rules also flag connections associated with certificates issued by 'TLC DV TLS CA' and known C2 infrastructure using the spoofed railway certificate.
Detects network activity related to the exploitation of the CVE-2025-31702 vulnerability in Dahua P2P Relay services. The rules monitor for probe attempts, device parameter fetching (randsalt), serial number enumeration bursts, and successful no-auth channel responses, indicating a bypass of authentication mechanisms on vulnerable Dahua devices.
Detects the creation of 'auth_codes.json' files within directories containing 'seria' in their path. This file is known to be used to store MD5-derived 8-character hex recovery codes for Dahua devices, allowing for password bypass or recovery via the easy4ipcloud.com portal without valid credentials.
Detects the execution of PowerShell commands that utilize .NET cryptography classes (AesManaged) in conjunction with data compression (GZipStream) and base64 decoding (FromBase64String). This combination of classes is highly characteristic of malicious scripts designed to decrypt and execute obfuscated or packed payloads in memory.
Detects high-volume, automated attempts to validate AWS credentials (access keys) from a single source IP address within a short time window. This pattern, characterized by a large number of distinct access keys being tested against identity-confirming API calls (e.g., GetCallerIdentity, AssumeRole) with a mix of success and failure, is indicative of automated credential harvesting or reconnaissance campaigns.
This rule detects mass-distributed email phishing campaigns that impersonate Google branding. It identifies emails using Google-related sender display names or subjects that originate from non-Google domains and contain links to external, non-Google domains. The detection focuses on identifying suspicious patterns across multiple recipients rather than individual email signatures.
This rule monitors cloud application events for high-frequency, automated API calls directed at AI/ML inference endpoints. A high volume of queries (over 1000) accessing a diverse range of objects (over 50) within a short window (60 minutes) by a single identity or IP address is flagged. Such behavior is characteristic of model extraction or distillation attacks, where an adversary probes an AI model to replicate its capabilities or internal parameters.
This rule monitors for high-frequency download or access events of files associated with AI development, such as model weights (.pt, .ckpt, .safetensors, .h5, .onnx, .pkl, .pb), checkpoints, and research datasets from cloud storage. It triggers when an account accesses or downloads 20 or more unique AI-related files within a 60-minute window, which is indicative of unauthorized data exfiltration of intellectual property.
Detects an accelerated sequence of attack phases—specifically recon, privilege escalation, lateral movement, and persistence—occurring on a single device within a short timeframe (15 minutes). This behavioral pattern indicates potential automated or script-orchestrated intrusion activity.


