Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the execution of 'mshta.exe' loading an .hta file containing specific suspicious terms ('VLC', 'Presentation', 'Denver'), followed by the spawning of child processes such as 'wscript.exe', 'cscript.exe', 'powershell.exe', 'cmd.exe', or 'wmic.exe'. This pattern is frequently used to proxy execution of malicious scripts via legitimate Windows binaries.
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This pattern can indicate suspicious activity where a legitimate updater process is being misused or abused to spawn additional malicious code or side-load components.
This rule detects the presence of a 7-Zip library file ('7z.dll') located within a specific 'Traiolx Custom Utils' directory. The rule flags this file based on known malicious file hashes (MD5 or SHA256) or its specific file path. This is indicative of an adversary placing custom or potentially malicious tools on a system for archive manipulation or data staging.
Detects the execution of a specific Visual Basic script named 'Telegram_Private_Call_Session.vbs' by Windows scripting utilities (wscript.exe, cscript.exe) or the Microsoft HTML Application host (mshta.exe). This pattern is often associated with the execution of malicious scripts disguised as legitimate communication application components.
Detects the execution of a PowerShell script named 'lightlife.ps1'. The rule flags instances where this specific script is invoked with bypass execution policies or when it is initiated by script hosts like wscript.exe or mshta.exe, which are common patterns for obfuscated or secondary script execution.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by using reflection to modify the 'amsiInitFailed' field within the 'AmsiUtils' class. This technique is commonly used by malicious scripts to disable AMSI scanning during their execution.
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, no profile, encoded command) initiated by wscript.exe or mshta.exe. This pattern is commonly used by adversaries to execute obfuscated malicious payloads while proxying the execution through legitimate Windows utilities.
Detects suspicious PowerShell command lines that utilize both 'Invoke-Expression' (iex) and 'Invoke-RestMethod' (irm), often used to download and execute code directly from remote sources. The rule specifically monitors for known indicators like specific IP addresses, file paths, or the concurrent use of these cmdlets in a single command line.
Detects attempts to disable PowerShell Script Block Logging via registry modification or by using the Set-ItemProperty command. Disabling this security feature prevents visibility into the actual contents of executed PowerShell scripts, which is a common tactic used by adversaries to evade detection.
Detects attempts to disable PowerShell Script Block Logging via registry modification or by using the Set-ItemProperty command. Disabling this security feature prevents visibility into the actual contents of executed PowerShell scripts, which is a common tactic used by adversaries to evade detection.
Detects outbound HTTP POST requests to a specific URL pattern (/board/fckeditor/userfiles/editor/board.php) associated with the Chinotto backdoor used by the APT37 threat group. The rule monitors for a specific Chrome user agent and a 'token=' cookie value, indicating a potential C2 check-in.
Detects the creation of scheduled tasks using schtasks.exe that are configured to run every minute, specifically targeting command lines associated with known suspicious processes like 'codeflush.exe' or potentially masqueraded music library tasks.
This rule detects the execution of common command-line or scripting tools (cmd.exe, powershell.exe, wscript.exe, cscript.exe, ftp.exe) or .lnk file handling triggered by explorer.exe immediately following the mounting of a VHD or VHDX file. This behavior is indicative of an attacker mounting a malicious virtual disk image and executing payloads contained within it.
Detects Python processes (python.exe, python3.exe, pythonw.exe) loading native library files (.pyd or .so) followed by file access to sensitive browser credential and cookie storage locations (e.g., Login Data, Cookies, Local State). This pattern is characteristic of infostealer activity, where a Python script uses a native module to decrypt or extract browser-stored credentials.
Detects file creation, renaming, or deletion events within the Recycle Bin directory involving suspicious filenames or PDF files, which may indicate an adversary attempting to hide, stage, or delete evidence.
This rule monitors for suspicious network traffic to SMTP services and specific external email addresses, as well as process command lines containing these indicators. Additionally, it tracks email events involving specific sender, recipient, and subject indicators which may be indicative of unauthorized communication or data exfiltration attempts.
Detects a sequence of multiple process injection-related API calls (VirtualAlloc, WriteProcessMemory, CreateRemoteThread) initiated by a process. This rule monitors for patterns indicating cross-process memory manipulation which is commonly used to inject malicious code into other processes. It specifically looks for API calls interacting with kernel32.dll and filters out known Microsoft security products.
Detects high-volume account existence checks targeting the Microsoft Teams API. The rule identifies anomalous authentication attempts characterized by the use of outdated Electron/Chrome user-agent strings associated with the TeamFiltration tool, specifically targeting the Microsoft Teams API AppId (1fec8e78-bce4-4aaf-ab1b-5451cc387264).
Detects two distinct suspicious activities on Android devices: the manual installation of an APK file using the 'pm' tool with specific flags, and the modification of security-sensitive settings to enable accessibility services via the 'settings' command. Both patterns are commonly associated with malicious Android applications or post-compromise activity.
Detects outbound network traffic attempting to interact with a specific Polygon smart contract address using eth_call. This behavior is indicative of the EtherHiding technique, where adversaries leverage blockchain infrastructure as a dead-drop resolver for command-and-control (C2) operations to bypass traditional network defenses.
This rule detects anomalous, high-volume activity in Jira, such as mass ticket viewing, searching, exporting, or attachment downloading, which is often characteristic of unauthorized data exfiltration or reconnaissance. The detection triggers when an account exceeds thresholds of 200 issue-related actions or 8 attachment downloads within a 7-day period.

