Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous AI agent behavior characterized by a significant spike in resource or tool invocations within a 15-minute window, potentially indicating indirect prompt injection or unauthorized agent hijacking where an agent is coerced into excessive or unauthorized actions.
Detects instances where the Windows Package Manager (winget.exe) initiates potentially suspicious child processes such as command shells or administrative tools, and correlates this activity with network connections originating from those child processes.
Detects a multi-stage process execution chain beginning with common end-user applications (browsers, Office apps, explorer.exe) spawning known LOLBins (Living-off-the-Land Binaries), which in turn execute secondary LOLBins with suspicious command-line indicators. This pattern often signifies post-exploitation activity such as secondary payload delivery, fileless malware execution, or proxy execution of malicious scripts/commands, consistent with ClickFix or BYOVD-related ingress techniques.
Detects high-volume authentication failures originating from a single source IP targeting multiple unique user accounts, indicative of password spraying or credential stuffing attacks against cloud identity providers.
This rule detects the suspicious creation or modification of local user accounts (e.g., 'svc_ipurple') occurring within a short 15-minute window following the execution of Windows Package Manager (Winget) configuration tasks. This behavior may indicate an attacker using automated configuration files (DSC) to establish persistence or escalate privileges on a compromised system.
Detects MSBuild.exe establishing a network connection to a specific remote IP address (212.34.141.103) on port 4521. This behavior is indicative of MSBuild being used to proxy execution of malicious code, often associated with downloading and executing second-stage payloads or beaconing to a command-and-control (C2) server.
This rule detects the loading of the 'Microsoft.Management.Configuration.dll' module by specific Windows system processes involved in package management and configuration, namely 'ConfigurationRemotingServer.exe' and 'WindowsPackageManagerServer.exe'. While these are legitimate components of the Windows Package Manager and DSC services, monitoring this activity can establish a baseline for identifying potential process injection or unauthorized library loading within these security-sensitive management binaries.
This rule monitors for suspicious activities involving digital certificates. It detects PowerShell processes attempting to import a certificate into the Root store, which could indicate persistence or credential interception, and it detects the use of curl to download files named 'cert.pem' with insecure SSL settings (no certificate verification).
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
KQL Query from file: FortiGate VPN Credential Abuse
Detects instances where Windows Terminal (WindowsTerminal.exe) is launched by Explorer and immediately spawns a shell process (PowerShell, PWSH, or CMD), specifically excluding devices that have recorded recent RunMRU registry history. This pattern may indicate suspicious or non-interactive execution by an adversary attempting to bypass traditional shell history tracking.
Detects suspicious execution of the certutil.exe utility for file operations, specifically targeting the copying of certutil or the decoding of files with naming patterns (kid*.exe, kid*.tmp, kid*.bat) within the \Users\Public\Downloads\ directory. This pattern is commonly associated with file staging and deobfuscation of malicious payloads.
Detects instances where PowerShell scripts perform Base64-encoded operations related to cryptographic functions and shortly thereafter establish network connections to known or suspect domains associated with C2 activity.
Detects ClickFix-style social engineering attacks where users are lured to 'cloudrobots.cloud' and subsequently execute malicious commands via Windows shell tools (cmd, powershell, mshta, etc.). The rule correlates browser network events to a specific domain, subsequent process launches by explorer.exe, and suspicious registry modifications associated with the Windows RunMRU, which is often abused to store and execute commands pasted by victims.
Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream from a file, effectively bypassing Mark-of-the-Web (MOTW) security protections. This behavior is often associated with the 'Unblock-File' cmdlet and is used by adversaries to execute downloaded malicious files without security warnings.
Detects the execution of 'mshta.exe' loading an .hta file containing specific suspicious terms ('VLC', 'Presentation', 'Denver'), followed by the spawning of child processes such as 'wscript.exe', 'cscript.exe', 'powershell.exe', 'cmd.exe', or 'wmic.exe'. This pattern is frequently used to proxy execution of malicious scripts via legitimate Windows binaries.
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This pattern can indicate suspicious activity where a legitimate updater process is being misused or abused to spawn additional malicious code or side-load components.
This rule detects the presence of a 7-Zip library file ('7z.dll') located within a specific 'Traiolx Custom Utils' directory. The rule flags this file based on known malicious file hashes (MD5 or SHA256) or its specific file path. This is indicative of an adversary placing custom or potentially malicious tools on a system for archive manipulation or data staging.
Detects the execution of a specific Visual Basic script named 'Telegram_Private_Call_Session.vbs' by Windows scripting utilities (wscript.exe, cscript.exe) or the Microsoft HTML Application host (mshta.exe). This pattern is often associated with the execution of malicious scripts disguised as legitimate communication application components.
Detects the execution of a PowerShell script named 'lightlife.ps1'. The rule flags instances where this specific script is invoked with bypass execution policies or when it is initiated by script hosts like wscript.exe or mshta.exe, which are common patterns for obfuscated or secondary script execution.

