Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects access to sensitive cryptocurrency wallet files (e.g., wallet.dat, keystore) by processes typically associated with LOLBins (Living-off-the-land Binaries) like PowerShell, MSBuild, or non-executable utilities. This activity is indicative of credential theft or data staging for exfiltration of cryptocurrency assets.
Detects the execution of PowerShell scripts containing specific obfuscation or encoding patterns. The rule identifies potential malicious intent by searching for hardcoded suspicious strings or common binary-to-string conversion methods used to hide script content from security monitoring.
Detects the execution of PowerShell or Unix shell commands (such as those containing encoded arguments, IEX, or clipboard reading) that are initiated by GUI-based applications or interactive shell environments like Windows Explorer, terminal emulators, or runtime brokers, often indicating potential malicious command injection or living-off-the-land activity.
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
Detects unauthorized code injection attempts into web browser processes (chrome.exe, msedge.exe) by non-browser related processes. This behavior involves using APIs like CreateRemoteThread, NtAllocateVirtualMemory, or NtWriteVirtualMemory to modify memory and execute remote threads, which is a common technique used by information stealers such as LummaC2 to bypass browser security controls.
This rule detects potential data staging activity associated with the REMUS malware. It correlates Windows Management Instrumentation (WMI) queries for antivirus information (e.g., 'AntiVirusProduct', 'WbemLocator') with subsequent file creation events in non-standard directories. This behavior is indicative of an adversary preparing or staging system profile data for exfiltration.
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
Detects execution of PowerShell or Python scripts characterized by common patterns found in AI-generated code, including specific obfuscation techniques (base64, string manipulation), boilerplate error handling structures, verbose comments, and generic variable naming conventions. High scores indicate a higher probability of automated or obfuscated script execution.
This rule identifies potential prompt injection attempts against Microsoft Copilot and Azure OpenAI services by monitoring CloudAppEvents for specific adversarial markers, encoded instruction blocks, or hidden text patterns. It flags recurring attempts from a single user as suspicious probing activity.
Detects network connections from server or workload identities (excluding SYSTEM) to known public Generative-AI inference API domains. This may indicate the use of AI services for data exfiltration, automated content generation, or C2 communication via legitimate web services.
Detects coordinated credential stuffing campaigns originating from shared IP infrastructure. The rule identifies patterns where multiple distinct accounts are targeted with failed sign-in attempts, characterized by rapidly rotating user-agent/device fingerprints while remaining under standard per-account and per-IP throttling limits. It focuses on the combination of high unique account counts, rotating user-agents, and sustained activity over a specific time window.
This rule monitors incoming email events for potential phishing attempts by identifying messages from unknown sender domains (not seen in the last 90 days) that contain known AI-generated response phrases in the subject line or personalized content matching the recipient's display name. This helps detect spearphishing lures that attempt to build trust through impersonation or leverage LLM-generated phrasing common in automated phishing campaigns.
Detects the transmission of sensitive credential-like patterns (such as API keys, private keys, and connection strings) to known external AI coding assistant and IDE plugin endpoints. This rule monitors cloud application events originating from developer workstations or CI/CD runners where such sensitive information may be inadvertently or maliciously sent to third-party AI services.
This rule detects potential data exfiltration by monitoring corporate user activities involving consumer generative AI services (e.g., ChatGPT, Gemini, Claude). It identifies suspicious patterns such as large volume submissions, repeated chunked prompts, and the presence of sensitive content (e.g., PII markers, classification labels) or obfuscated payloads (base64/rot13) that suggest an attempt to bypass DLP or detection controls.
Detects autonomous AI coding-agent processes (e.g., Claude Code, Cursor, Aider) spawning shell or git processes to perform potentially destructive actions such as recursive file deletion, forced git pushes, database manipulation, or unauthorized access to sensitive credential files, indicating agentic 'excessive agency' or compromise.
Detects evidence of indirect prompt injection (IPI) attempts within email and document content processed by enterprise AI assistants. The rule flags instruction-hijack phrases, hidden obfuscation characters (e.g., zero-width, white-on-white text), and encoded blocks specifically targeting AI model behavior.
Detects large outbound POST requests or file uploads from managed endpoints to public,
consumer-grade generative-AI chatbot domains (ChatGPT, Gemini, and equivalents). Data pasted
or uploaded into these services may be retained by the provider for logging or model
training outside company control, representing a persistent shadow-AI governance gap.
This detects the network-observable behavior (large uploads to these domains); confirming
the payload contains classification markers, source code, or PII/PCI requires DLP content
inspection integrated with the proxy.
consumer-grade generative-AI chatbot domains (ChatGPT, Gemini, and equivalents). Data pasted
or uploaded into these services may be retained by the provider for logging or model
training outside company control, representing a persistent shadow-AI governance gap.
This detects the network-observable behavior (large uploads to these domains); confirming
the payload contains classification markers, source code, or PII/PCI requires DLP content
inspection integrated with the proxy.
Detects video and audio conferencing clients (e.g., Zoom, Microsoft Teams, Webex) loading either unsigned DLLs or DLLs commonly associated with virtual camera and audio injection tools (e.g., OBS VirtualCam, Snap Camera). This behavior is characteristic of deepfake injection techniques used to manipulate video conference participants.
Detects web reconnaissance activity characterized by the use of User-Agent strings associated with automated AI agent frameworks and headless browser libraries (e.g., LangChain, AutoGPT, Playwright, Selenium, python-requests). These tools are frequently utilized in autonomous exploitation scenarios to scan multiple URI paths on a web server in a short timeframe.
The following analytic identifies the `finger.exe` utility being spawned with a command line containing an `@` character, indicating a remote host/server was specified.
The Finger protocol utility is largely obsolete in modern environments and has been abused by adversaries as a living-off-the-land binary (LOLBIN) to retrieve encoded payloads or establish covert command-and-control communication with an attacker-controlled finger server.
This behavior is uncommon in legitimate enterprise usage and warrants investigation.
The Finger protocol utility is largely obsolete in modern environments and has been abused by adversaries as a living-off-the-land binary (LOLBIN) to retrieve encoded payloads or establish covert command-and-control communication with an attacker-controlled finger server.
This behavior is uncommon in legitimate enterprise usage and warrants investigation.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.


