Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
This rule detects a multi-stage Business Email Compromise (BEC) attack involving executive impersonation via look-alike domains, followed by the creation of suspicious inbox rules (forwarding/deletion) by the victim, and concurrent external communication (Teams/Zoom meeting invites) from a newly created account. It correlates these activities to identify sophisticated payment fraud campaigns.
Detects unauthorized data staging activities using archival utilities followed by data exfiltration to known public cloud storage providers. The rule specifically excludes hosts experiencing mass file renaming activity, focusing on extortion-only scenarios where data is stolen without encryption.
Detects a sequence of events indicative of Bring Your Own Vulnerable Driver (BYOVD) exploitation. The rule correlates the creation of a new service with kernel-mode drivers, the loading of a signed driver, and the subsequent termination or disabling of common EDR security processes within a short timeframe, suggesting the exploitation of the driver to bypass EDR defenses.
This rule detects potential 'Quishing' (QR code phishing) attempts by identifying email-based phishing detection or malicious URL indicators followed by a user clicking the URL and subsequently authenticating to a corporate system from a mobile device (Android or iOS) within a 30-minute window. This behavior often suggests an adversary successfully harvesting credentials via a QR code link and then using them to gain unauthorized access.
Detects the use of legitimate Windows administrative tools (vssadmin, wmic, wbadmin, bcdedit, sc, net) to delete volume shadow copies, clear backup catalogs, disable boot recovery options, or stop critical backup and system services. This behavior is highly characteristic of ransomware activity aiming to prevent data restoration and system recovery.
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
Detects the execution of 'tscon.exe', a Windows utility used to control Remote Desktop sessions. The rule specifically alerts when 'tscon.exe' is executed with parameters indicative of session hijacking (such as '/dest:') or when it is invoked by suspicious processes or under SYSTEM privileges, which are characteristic of RDP session hijacking techniques used for privilege escalation and lateral movement.
Detects the execution of known Living-off-the-Land Binaries (LOLBAS) like mshta, rundll32, regsvr32, and others, when the command line includes indicators of external network retrieval (http/ftp), script execution (javascript/vbscript), or common obfuscation/decoding patterns (base64, encodedcommand). The rule excludes paths within System32 and SysWOW64 to focus on potentially suspicious locations or renamed binaries.
This rule detects potential Kerberoasting activity by identifying an abnormal volume of RC4-encrypted Ticket Granting Service (TGS) requests (Event 4769) targeting service accounts, followed closely by a successful logon (Event 4624) from a previously dormant service account, suggesting the successful use of a cracked service ticket for unauthorized authentication.
Detects attempts to tamper with, disable, or delete audit logging configurations in AWS CloudTrail and Azure Monitor. Monitoring these activities is critical to ensure that audit logs remain intact for security investigations.
Detects potential credential dumping activity via DCSync, identified by a non-DC computer account performing directory replication (DRS GetNCChanges), correlated with subsequent suspicious Kerberos ticket requests (Event ID 4769) that utilize weak encryption (RC4 or legacy DES), which is often associated with Golden Ticket abuse.
No description available.
Detects instances where a user successfully authenticates to a cloud service (Azure AD) from an unrecognized ASN, device, or country without performing MFA, followed shortly by high-risk actions such as mailbox rule creation, mass file downloads, or OAuth application registration. This pattern is indicative of session cookie theft or OAuth token replay used to bypass MFA.
Detects a ClickFix-style activity where an adversary uses nslookup.exe or certutil.exe to perform DNS TXT record queries for payload staging or C2 rendezvous. The rule identifies suspicious parent processes like explorer.exe or scripting hosts, correlates this with a subsequent outbound network connection from the same host, and is intended to capture DNS-based beaconing or data staging.
Detects the clearing of Windows Event Logs via wevtutil, PowerShell, or registry modification, occurring within one hour of a remote interactive or network logon event on the same host. This pattern is indicative of anti-forensic activity often performed following lateral movement or prior to destructive actions like ransomware deployment.
Detects a suspicious pattern consistent with rapid handoff from an initial access broker to an operator: a user account is added to a privileged group (e.g., Domain Admins) followed within 5 minutes by successful logins to 3 or more distinct hosts. This behavior indicates immediate privilege escalation followed by rapid lateral movement.
Detects a sequence of activity indicative of data exfiltration preparation. This rule identifies the creation of multiple large archive files (.zip, .rar, .7z) in temporary or staging directories on an endpoint, followed by a network connection transferring a significant volume of data to an external, non-private IP address within a 30-minute window.
Detects the execution of PsExec by identifying the creation of the PSEXESVC remote service or its associated named pipe. It also identifies renamed or masqueraded PsExec binaries by checking file metadata and provides a mechanism to flag unusual source-to-target host account pairings often associated with lateral movement via SMB/Admin Shares.
Detects specific file artifacts associated with an AsyncRAT infection chain that leverages a renamed AutoIT interpreter. The rule looks for the presence of a renamed executable, an encrypted .ini loader script, and an unnamed binary payload staged within a temporary directory, as well as associated batch script activity.
