Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects network connections from monitored devices to known cryptomining pool IP addresses and domain names. It monitors DeviceNetworkEvents for indicators of compromise (IOCs) associated with cryptomining activities, identifying potential resource hijacking on internal endpoints.
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
Detects anomalous Telnet (TCP port 23) traffic associated with Mirai-variant botnet propagation, such as scanning for new targets or inbound compromise attempts, often following cPanel/WHM vulnerabilities.
Detects potential exploitation of CVE-2026-41940 affecting cPanel/WHM, where administrative actions occur without a preceding successful login event from the same source IP within a 30-minute window. This indicates an authentication bypass attempt.
KQL Query
KQL Query
KQL Query
KQL Query
KQL Query
KQL Query
This rule detects malicious activity associated with the Bazinga macOS backdoor, specifically focusing on the clearing of TCC privacy permissions, the staging of keychain and browser data using 'ditto', and the subsequent exfiltration of this data to a remote host via 'curl'.
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
Detects indicators of the Bazinga macOS backdoor and Polygon-C2 campaign, including specific command-and-control domains, C2 infrastructure IP addresses, persistence mechanisms via launch agent property lists, and associated cryptographic indicators like file hashes and wallet addresses.

