Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where a trusted, system-protected executable loads a DLL file from a user-writable or temporary directory that is not digitally signed or has an invalid signature. This is a common indicator of DLL side-loading or DLL hijacking, where an adversary attempts to execute malicious code by placing a malicious DLL in a location searched by a legitimate process.
Detects the use of the BITSAdmin command-line utility to perform file downloads or add files to a transfer job. Adversaries may abuse the Background Intelligent Transfer Service (BITS) for downloading malicious files while evading detection or maintaining persistence.
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
Detects a sequence of suspicious identity activities indicative of a post-account-takeover pivot. The rule identifies a user profile engaging in corporate VPN SAML SSO probing, triggering a MFA enrollment interrupt in Azure, and subsequently accessing multiple Microsoft 365 applications (Azure Portal, OfficeHome, SharePoint) within a 30-minute window.
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
This rule detects a malicious execution chain starting with an MSI file being launched by explorer.exe from user-downloaded folders. The installer spawns chrome.exe, drops a specific loader file (e.g., PavokwiLoader.exe or Loader.exe) into the %LOCALAPPDATA%\Temp\modules\ directory, and establishes persistence via the HKCU 'Load' registry value pointing to that location.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects high-volume account existence checks targeting the Microsoft Teams API. The rule identifies anomalous authentication attempts characterized by the use of outdated Electron/Chrome user-agent strings associated with the TeamFiltration tool, specifically targeting the Microsoft Teams API AppId (1fec8e78-bce4-4aaf-ab1b-5451cc387264).
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
Detects suspicious processes such as PowerShell, Python, or scripting hosts performing network communication with major AI/LLM provider APIs, followed immediately by child process execution or related activity. This pattern is indicative of LLM-assisted automation for malicious activities, potentially using AI to generate code, scripts, or orchestrate command and control actions.
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
Detects instances where a user successfully authenticates via the OAuth Device Code flow using an unmanaged or non-compliant device, followed closely by high-privileged Azure/Graph API administrative actions within a short timeframe. This behavior is indicative of a device-code phishing attack aimed at bypassing MFA controls, including FIDO2/passkeys, by compromising an active session.
Detects potential Adversary-in-the-Middle (AiTM) session token theft by monitoring for an initial interactive sign-in followed shortly by a non-interactive token refresh from a different IP address and browser fingerprint without a multi-factor authentication (MFA) challenge. This behavior is indicative of an adversary replaying captured session cookies via reverse-proxy infrastructure.
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
Detects potential Adversary-in-the-Middle (AiTM) session token theft by monitoring for an initial interactive sign-in followed shortly by a non-interactive token refresh from a different IP address and browser fingerprint without a multi-factor authentication (MFA) challenge. This behavior is indicative of an adversary replaying captured session cookies via reverse-proxy infrastructure.
Detects instances where a user successfully authenticates via the OAuth Device Code flow using an unmanaged or non-compliant device, followed closely by high-privileged Azure/Graph API administrative actions within a short timeframe. This behavior is indicative of a device-code phishing attack aimed at bypassing MFA controls, including FIDO2/passkeys, by compromising an active session.

