Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation of a .bat file in the Windows Startup directory, followed by the execution of a command process from a temporary location using a specific command line pattern. This behavior is indicative of persistent malware or a dropper attempting to execute an initial payload upon user logon.
This rule monitors for two potentially suspicious activities on Windows systems: the creation of scheduled tasks named 'MicrosoftEdgeUpdateTask' or 'MicrosoftEdgeUpdateTaskCore' using 'schtasks.exe', and the execution of scripts via 'wscript.exe' with silent flags ('//B' and '//Nologo'). These behaviors are often associated with persistence mechanisms or the execution of obfuscated/malicious scripts.
Detects a coordinated attack sequence where a browser process is terminated, followed immediately by the execution of an unsigned Python interpreter from a suspicious location (temp/downloads folder), which is then followed by the installation of an unsigned browser extension. This pattern mimics ClickFix and browser-based RAT lure campaigns.
Detects unauthorized processes attempting to read or modify Discord's local storage leveldb files, which store user authentication tokens, and correlates this with suspicious network activity to Discord's API or the presence of token-stealing keywords in command-line arguments.
This rule detects potential usage of Hidden VNC (hVNC) tools by monitoring for specific command-line arguments (such as 'hvnc-input', 'hvnc-desktop', or 'HVNC_Telegram') and Windows events related to the creation or switching of desktops (e.g., 'CreateDesktop', 'SwitchDesktop'). hVNC is a common technique used by malware to establish a hidden remote desktop session for unauthorized access and control without alerting the user.
Detects MFA push-bombing or authentication fatigue attacks where an adversary repeatedly triggers MFA challenge requests for a user in a short period, potentially from multiple IP addresses, culminating in a successful authentication event. This behavior is indicative of an attacker attempting to coerce a user into approving an MFA request.
Detects anomalous authentication behavior consistent with Adversary-in-the-Middle (AiTM) phishing attacks, specifically where an MFA-authenticated session is accessed from multiple, disjoint geographic locations or IP addresses within a short timeframe, indicating the replay of stolen session tokens.
Detects anomalous authentication behavior consistent with Adversary-in-the-Middle (AiTM) phishing attacks, specifically where an MFA-authenticated session is accessed from multiple, disjoint geographic locations or IP addresses within a short timeframe, indicating the replay of stolen session tokens.
Detects the installation or loading of a non-standard kernel driver followed by the termination of known security/EDR agent processes. This behavior is indicative of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where attackers leverage kernel-level privileges from a vulnerable driver to bypass EDR protections and disable security tools prior to encryption or other malicious activities.
Detects a suspicious pattern of mass security process termination, where a process masquerading as legitimate consumer or gaming software (e.g., Kaspersky, Valorant, Javelin) repeatedly uses commands like taskkill, sc stop, or NtTerminateProcess to disable EDR agents and antivirus software within a short time window. This behavior is indicative of pre-ransomware staging activities used by threat actors.
Detects a suspected ransomware double-extortion sequence: the bulk creation of password-protected archives using compression utilities (e.g., 7z, RAR), followed by significant outbound network connections to common cloud storage or anonymization endpoints, and concluding with mass file modifications indicative of encryption activity.
Detects anomalous activity in a CI/CD environment where a runner process accesses sensitive credential files (such as PyPI tokens or GitHub secrets) followed closely by a network connection to public package registry domains, potentially indicating a supply-chain compromise where stolen credentials are used to publish malicious packages.
Detects package publishing or version creation events on npm or PyPI that originate from non-CI/CD service accounts, suggesting the use of stolen registry authentication tokens by unauthorized entities to push malicious package versions.
Detects unauthorized, unsigned processes accessing sensitive browser files (Cookies, Login Data, Local State) across common browsers (Chrome, Edge, Brave, Firefox) followed by an outbound network connection. This behavior is indicative of credential-harvesting infostealer malware.
Detects anomalous AI agent behavior characterized by a significant spike in resource or tool invocations within a 15-minute window, potentially indicating indirect prompt injection or unauthorized agent hijacking where an agent is coerced into excessive or unauthorized actions.
Detects instances where the Windows Package Manager (winget.exe) initiates potentially suspicious child processes such as command shells or administrative tools, and correlates this activity with network connections originating from those child processes.
Detects a multi-stage process execution chain beginning with common end-user applications (browsers, Office apps, explorer.exe) spawning known LOLBins (Living-off-the-Land Binaries), which in turn execute secondary LOLBins with suspicious command-line indicators. This pattern often signifies post-exploitation activity such as secondary payload delivery, fileless malware execution, or proxy execution of malicious scripts/commands, consistent with ClickFix or BYOVD-related ingress techniques.
Detects high-volume authentication failures originating from a single source IP targeting multiple unique user accounts, indicative of password spraying or credential stuffing attacks against cloud identity providers.
This rule detects the suspicious creation or modification of local user accounts (e.g., 'svc_ipurple') occurring within a short 15-minute window following the execution of Windows Package Manager (Winget) configuration tasks. This behavior may indicate an attacker using automated configuration files (DSC) to establish persistence or escalate privileges on a compromised system.
Detects MSBuild.exe establishing a network connection to a specific remote IP address (212.34.141.103) on port 4521. This behavior is indicative of MSBuild being used to proxy execution of malicious code, often associated with downloading and executing second-stage payloads or beaconing to a command-and-control (C2) server.
This rule detects the loading of the 'Microsoft.Management.Configuration.dll' module by specific Windows system processes involved in package management and configuration, namely 'ConfigurationRemotingServer.exe' and 'WindowsPackageManagerServer.exe'. While these are legitimate components of the Windows Package Manager and DSC services, monitoring this activity can establish a baseline for identifying potential process injection or unauthorized library loading within these security-sensitive management binaries.
