Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects scripting interpreters (wscript.exe, cscript.exe, powershell.exe, python.exe) that perform an outbound network connection to known public Generative AI API endpoints and subsequently modify their own script file on disk. This behavior is indicative of sophisticated malware attempting to rewrite its own source code at runtime to evade signature-based detection.
Detects a credential stuffing attack characterized by a high volume of failed authentication attempts from a small set of source IP addresses followed by a successful authentication within a short timeframe. This behavior is indicative of an attacker attempting to use valid credentials obtained from infostealer logs or credential leaks to gain unauthorized access to accounts.
Detects MFA method resets, security info updates, or new authentication device registrations targeting privileged or administrator accounts in Azure AD/Entra ID audit logs. This activity is often indicative of social engineering campaigns, including AI-driven voice or video deepfake impersonation of employees contacting helpdesk support to gain unauthorized account access.
This rule detects potential lateral movement by identifying a system that initiates SMB connections (port 445) to 5 or more unique destinations, correlated with a Windows Service installation event (Event ID 7045) on the host. This behavior is indicative of an adversary or automated tool using SMB to copy and execute binaries as a service on multiple remote systems.
This rule detects successful user logins from multiple geographical locations (impossible travel) where multi-factor authentication (MFA) was not utilized. This behavior is indicative of credential theft or account takeover attempts.
This rule detects a correlation between an Active Directory Certificate Services (AD CS) certificate request (Event ID 4887) containing certificate attributes (SAN, altname, or UPN) and a subsequent Kerberos TGT request (Event ID 4768) within an hour, where the requested account name does not match the ticket user. This behavior is indicative of potential certificate-based authentication abuse, such as 'ESC1' or 'Golden Certificate' attacks where a certificate is requested and immediately used for credential impersonation.
Detects the use of common administrative tools (vssadmin, wbadmin, wmic, bcdedit, etc.) to perform actions that inhibit system recovery. This includes deleting Volume Shadow Copies, deleting backup catalogs, disabling system recovery boot policies, and stopping backup-related services, which are common behaviors used by ransomware to prevent data restoration.
Detects anomalous child process execution (e.g., shells, curl, python) or the creation of web-accessible script files (.jsp, .php, .aspx) originating from common VPN gateway or edge appliance service processes. This behavior is indicative of potential exploitation of a remote-facing appliance or webshell deployment.
Detects suspicious activity on VMware ESXi hosts involving the termination or unregistration of virtual machines via 'esxcli' or 'vim-cmd', correlated with high volumes of file modification or creation events (.vmdk or .vmx files) within a short window. This pattern often indicates attempts to disrupt virtual machines or inhibit system recovery by adversaries.
Detects the installation of a new Windows service where the executable path is located in suspicious or uncommon directories (e.g., Temp, Users, AppData) or uses known living-off-the-land binaries (LotLBin) in the command path. This pattern is commonly used by adversaries for persistence and privilege escalation.
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) using weak encryption (RC4/0x17) directed at multiple unique Service Principal Names (SPNs) from a single host or user within a short timeframe. This behavior is indicative of Kerberoasting, a technique used by attackers to harvest service account credentials for offline brute-force cracking.
Detects a single host or account generating a high volume of LDAP queries (typical of reconnaissance tools like BloodHound/SharpHound) within a 10-minute time window. The rule specifically looks for more than 500 LDAP queries targeted at a limited number of Domain Controllers.
Detects instances where PowerShell is executed with encoded commands, seemingly spawned by a process masquerading as or related to the Microsoft Edge Update Task. The rule specifically monitors for process chains involving 'conhost.exe' with '--headless' arguments and subsequent PowerShell execution containing encoded commands, often associated with obfuscated activity.
Detects SAML token authentication events where the token-signing certificate does not match the established federation baseline (indicating potential token forging or unauthorized IdP activity) or where critical conditional access claims (MFA and device compliance) are missing from the SAML assertion.
Detects NTLM network logon events (Logon Type 3) using the NtLmSsp process where the key length is zero. This pattern is often indicative of Pass-the-Hash (PtH) attacks where the adversary uses a NTLM hash for authentication without knowing the original plaintext password.
This rule detects two suspicious patterns related to authentication: (1) 'MFA Fatigue' or 'Push Bombing' where a user experiences a high volume of MFA push denials followed by an acceptance in a short timeframe, and (2) potential account takeover where a help-desk initiated password reset is followed by an MFA re-registration or new device enrollment by the same user within 30 minutes.
Detects the creation or writing of disk image files (.iso, .img, .vhd, .vhdx) followed by the execution of suspicious file types (.lnk, .exe, .js, .vbs, .cmd, .bat, .scr) by explorer.exe within a 10-minute window. This behavior is indicative of an adversary using container files to bypass security controls or execute malicious payloads from mounted images.
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects usage of the Windows certutil.exe utility with flags commonly used by adversaries to download files from remote URLs or decode base64 encoded files. These techniques are often utilized for ingress tool transfer or deobfuscating malicious payloads.
Detects the execution of PowerShell commands that enumerate files within sensitive user directories such as Desktop, Downloads, Documents, or OneDrive, using common cmdlets like Get-ChildItem with recurrence or filtering. This behavior is indicative of an adversary attempting to discover or stage files for exfiltration.

