Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Detects a suspicious sequence of events where msiexec.exe is launched by explorer.exe, subsequently spawning a suspended chrome.exe process. This is followed by the creation of a 'PavokwiLoader.exe' file in a 'Temp\modules' directory and the establishment of persistence by setting the 'Load' value within the 'HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows' registry key to execute the dropped loader.
This rule detects a suspicious process execution chain where a Chrome browser process launches cmd.exe, which subsequently spawns a setup executable (setup.exe or setup.tmp), leading to the execution of 7za.exe or a Python script/artifact. This pattern is indicative of a multi-stage malware execution chain, often involving the extraction or execution of payloads dropped via web-based sources.
This rule detects when the Node.js runtime process (node.exe) initiates the Windows command interpreter (cmd.exe) with the '/c' flag, which is commonly used to execute commands or scripts. This behavior is frequently associated with malicious Node.js activity, such as Remote Access Trojans (RATs) or web shells, which may use the shell to execute system-level operations or bypass typical application constraints.
Detects a suspicious execution chain where a command shell (cmd.exe) launched by explorer.exe uses curl.exe to download an MSI file from Azure Blob Storage, followed immediately by the installation of that MSI using msiexec.exe. This pattern is indicative of common malware delivery techniques, such as those observed with the RVTools.lnk delivery chain.
This rule detects suspicious activity where a node.exe process, often associated with a node-pty terminal emulation, launches common Windows command-line shells (cmd.exe, powershell.exe) from specific file paths or directories. This behavior is indicative of a Node.js-based Remote Access Trojan (RAT) or shell spawning mechanism being used to establish command and control or persistence on a Windows host.
This rule detects potential screen capture activity performed by either a suspicious executable (SearchTrustedRuntimeSvc.exe) that mimics a screen capture tool or a PowerShell script invoked by Node.js using .NET drawing libraries. This behavior is indicative of unauthorized information gathering, common in remote access trojans (RATs).
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
Detects the execution of PowerShell with command-line arguments that suggest programmatically capturing or redirecting console output using ScriptBlock techniques (Create, Console, In, ReadToEnd). This pattern is often associated with obfuscated script execution, in-memory payloads, or attempts to bypass logging by capturing output via .NET streams.
Detects instances where Python interpreters (python.exe or pythonw.exe) are executed from a subdirectory within ProgramData that matches a 32-hex character pattern, initiated by the 7zip archive utility (7za.exe). This pattern is indicative of a self-extracting archive or malicious installer unpacking and executing Python scripts in a stealthy, non-standard location.
This rule detects rundll32.exe executing a DLL from the ProgramData directory and subsequently establishing five or more outbound network connections to external IP addresses over non-standard ports (excluding 80 and 443) within a one-hour window. This behavior is indicative of a potential malware beaconing or data staging activity using a proxy binary to evade detection.
This rule detects a malicious execution chain starting with an MSI file being launched by explorer.exe from user-downloaded folders. The installer spawns chrome.exe, drops a specific loader file (e.g., PavokwiLoader.exe or Loader.exe) into the %LOCALAPPDATA%\Temp\modules\ directory, and establishes persistence via the HKCU 'Load' registry value pointing to that location.
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
KQL Query
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
This rule monitors network traffic and DNS queries to identify endpoints attempting to connect to known cryptocurrency scam domains. It correlates data from DeviceNetworkEvents and DnsEvents to capture both direct network connections and DNS resolution attempts.


