Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects coordinated usage of 'xattr' to manipulate the com.apple.quarantine attribute and 'chmod' to grant executable permissions on sensitive macOS system or library paths. This behavior is indicative of an adversary attempting to bypass Gatekeeper or bypass execution restrictions on malicious payloads placed in system directories.
The following analytic detects the usage of wevtutil.exe with parameters for clearing event logs such as Application, Security, Setup, Trace, or System.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments.
This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
If confirmed malicious, this behavior could allow an attacker to erase evidence of their activities, making it difficult to trace their actions and understand the full scope of the compromise.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments.
This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
If confirmed malicious, this behavior could allow an attacker to erase evidence of their activities, making it difficult to trace their actions and understand the full scope of the compromise.
Detects incoming HTTP requests where the 'pagename' parameter contains directory traversal sequences (e.g., '../', '..%2f'). These attempts are typically indicative of automated vulnerability scanning or exploitation attempts targeting WordPress page-template resolution logic, specifically related to CVE-2026-87902.
Detects Node.js or NPM process executions that reference Twilio-specific credential variables (ACCOUNT_SID, AUTH_TOKEN) within the command line, likely indicating an attempt to harvest these secrets from a developer environment.
Detects the installation of a specific malicious Firefox browser extension identified by its unique internal ID 'pdf-para-texto@extensao.local' or by its name 'PDF Identity Verifier'. This behavior is characteristic of adversaries using browser extensions for persistence or credential theft.
Detects Node.js processes, such as npm package postinstall hooks, spawning shell commands used for host enumeration. This includes accessing system environment variables, network configurations, and filesystem metadata, a pattern frequently utilized by malicious packages for initial reconnaissance post-installation.
Detects instances where the Firefox browser or its plugin container process initiates a DNS query for domains containing 'pdf.gusercontent.com', which is a known lookalike pattern used to masquerade as legitimate Google infrastructure for potential command and control or data exfiltration activities.
Detects the execution of piped curl-to-shell or curl-to-bash commands originating from a macOS Terminal process, a common pattern used in ClickFix-style social engineering attacks where users are tricked into copying and pasting malicious commands.
Detects instances where a suspicious login event (such as a risk challenge) is immediately followed by a credential or recovery information modification. This pattern may indicate an adversary is attempting to take over a compromised account by resetting the password or recovery details after triggering a security alert.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
Detects instances where AI-assisted development tools (such as Claude, Codex, Copilot, or Gemini) initiate command-line processes (e.g., shells, interpreters, or network utilities) with arguments indicative of credential access, reconnaissance, or sensitive file interactions.
Detects ClickFix-style social engineering attacks where users are tricked into pasting malicious payloads into the Windows Run dialog. The rule monitors for common scripting interpreters (powershell.exe, cmd.exe, mshta.exe, rundll32.exe) spawned by explorer.exe or mstsc.exe with suspicious command-line patterns indicative of payload delivery, such as obfuscated strings, hidden windows, or short-URL downloads.
Detects instances where end users grant high-risk delegated permissions (e.g., Mail.Read, Files.ReadWrite.All) to applications via OAuth consent flows outside of standard administrator approval processes. This behavior is indicative of device-code phishing or consent phishing campaigns designed to gain unauthorized access to user data.
Detects instances where a signed executable, typically a security or trusted system binary, loads an unsigned DLL from a user-writable, non-default directory (e.g., Temp, AppData, ProgramData). The rule specifically targets common system or vendor library names, indicating potential DLL search-order hijacking used to execute malicious code within a trusted process context.
Detects instances where an existing, non-interactive SSO session token is reused from a suspicious network location, such as an anonymizing proxy, VPN, or VPS, or triggered by an impossible travel risk event. The rule specifically looks for token usage that lacks a fresh interactive Multi-Factor Authentication (MFA) challenge, a common indicator of session token hijacking or 'replay' attacks frequently used in cloud account takeover campaigns.
Detects HTTP requests directed at edge appliances (FortiOS/FortiProxy, SonicWall, Cisco ASA) that match known CVE-associated URI paths, alongside successful administrative authentication to management or VPN interfaces originating from external source IP addresses. This rule is designed to identify potential initial access via vulnerability exploitation or unauthorized administrative login to critical infrastructure.
Detects malicious processes or scripts that perform multi-stage environment fingerprinting to identify virtualization or sandbox environments. The rule identifies chains of suspicious activities, including querying registry keys related to virtualization (e.g., VMware, VirtualBox, QEMU), WMI queries for BIOS/Computer system details, API calls common to sandbox evasion (GetCursorPos, GetTickCount), and artificial execution delays (sleep/timeout), typically used by malware like LummaC2 to perform conditional exits if an analysis environment is detected.
Detects the loading of a legitimately signed but vulnerable driver from suspicious directories (e.g., Temp, Downloads) followed closely by the termination of critical security/EDR service processes. This sequence is indicative of Bring Your Own Vulnerable Driver (BYOVD) exploitation used to disable security controls prior to ransomware deployment.
Detects browser processes performing JSON-RPC network connections to known public blockchain node providers, a network behavior characteristic of the EtherHiding technique used by the ErrTraffic MaaS platform to resolve C2 infrastructure via smart contracts. This rule identifies the network-side beaconing and should be correlated with suspicious process execution chains (e.g., browser-spawned PowerShell/cmd).


