Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
Detects the inclusion of PowerShell download commands ('irm' or 'Invoke-RestMethod') within the Windows 'RunMRU' registry key. This key is used by Windows Explorer to track recently typed run commands, and adversaries often abuse it to maintain persistence or store malicious one-liner payloads that are intended to be executed at a later time.
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
Detects outbound network connections from endpoints to domains and IP addresses associated with the Kimsuky (APT43) threat actor group. This rule leverages endpoint network telemetry to identify potential command and control (C2) communication or data exfiltration activities.
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
Detects an exploitation attempt against the Vite Development Server (CVE-2026-39364) where an attacker uses specific query parameters to bypass file access restrictions and disclose sensitive files. The rule triggers on GET requests containing suspicious import-related query parameters and checks the resulting response to ensure a successful 200/206 status code and non-HTML content type.
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
BigBear 2.0 IOC HUNT (Cortex XDR)
Cortex XDR
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
Page 309 of 1871



