Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a specific pattern associated with AvisLoader or similar malware: a device establishes a network connection to known Cloudflare Tunnel infrastructure domains (trycloudflare.com or workers.dev), followed by the creation and execution of an executable file (.exe, .dll, or .scr) in user-writable directories such as Downloads, AppData, or Temp within a 15-minute window.
This rule detects the presence and execution of known suspicious files (hashes provided) or specific malicious artifacts, such as 'hmn_hook.dll' being loaded, or the execution of binaries named 'auto.exe' and '78324.exe' associated with specific command-line arguments. It monitors file events, image loads, and process creation to identify potential malware activity.
This rule detects potential quishing (QR code phishing) attempts by identifying emails with one or more image attachments and minimal URL content, followed by a risky user authentication event within a 3-hour window. This behavior is indicative of an attacker attempting to harvest credentials via a malicious QR code that redirects the user to a phishing site.
Detects high-volume, rapid enumeration of core Microsoft Graph directory endpoints (users, groups, applications, and servicePrincipals) by a single identity or session. This behavior is indicative of reconnaissance tools such as AADInternals, ROADtools, or TokenTactic being used to map out a cloud environment's directory structure.
Detects Microsoft Entra ID service principal (app-only) sign-in events where an application accesses a resource or tenant that has not been observed in the previous 30 days. This is often an indicator of cross-tenant impersonation abuse or credential misuse, particularly related to Actor Tokens.
Detects scenarios where a user registers a new WebAuthn/Passkey credential and subsequently performs a sign-in from a different network or device shortly after, preceded by a sign-in from a risky or non-passkey-based method. This pattern is often associated with credential abuse or MFA registration hijacking.
Detects scenarios where a user registers a new WebAuthn/Passkey credential and subsequently performs a sign-in from a different network or device shortly after, preceded by a sign-in from a risky or non-passkey-based method. This pattern is often associated with credential abuse or MFA registration hijacking.
Detects scenarios where a user registers a new WebAuthn/Passkey credential and subsequently performs a sign-in from a different network or device shortly after, preceded by a sign-in from a risky or non-passkey-based method. This pattern is often associated with credential abuse or MFA registration hijacking.
This rule identifies instances of screen capture events initiated by processes that have previously engaged in network communication with known Remote Management Tool (RMM) domains. By correlating network activity with suspicious endpoint events, it flags potential unauthorized screen scraping performed by tools often abused by attackers for post-compromise reconnaissance.
This rule detects potential quishing (QR code phishing) attempts by identifying emails with one or more image attachments and minimal URL content, followed by a risky user authentication event within a 3-hour window. This behavior is indicative of an attacker attempting to harvest credentials via a malicious QR code that redirects the user to a phishing site.
Detects Microsoft Entra ID service principal (app-only) sign-in events where an application accesses a resource or tenant that has not been observed in the previous 30 days. This is often an indicator of cross-tenant impersonation abuse or credential misuse, particularly related to Actor Tokens.
Detects the addition or modification of federated domain trusts or identity provider settings within Entra ID. Such actions can be indicative of attackers establishing persistent access or implementing Golden SAML-style attacks by forging authentication assertions via a compromised or malicious identity trust.
Detects Microsoft Entra Privileged Identity Management (PIM) activations for high-privileged roles (e.g., Global Administrator) that occur outside of defined business hours or are performed without an associated justification or ticket number. This helps identify potentially unauthorized or abnormal use of elevated privileges.
Detects malformed HEIF/HEIC image files with anomalous ftyp/box structure consistent with the libheif memory corruption exploit (CVE-2026-32882) used against Discourse forum image upload endpoints
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
Detects high-volume, rapid enumeration of core Microsoft Graph directory endpoints (users, groups, applications, and servicePrincipals) by a single identity or session. This behavior is indicative of reconnaissance tools such as AADInternals, ROADtools, or TokenTactic being used to map out a cloud environment's directory structure.
Detects a single user identity performing bulk destructive device actions (wipe, retire, remote lock, or delete) against multiple distinct devices within a short timeframe. This activity is indicative of potential unauthorized access and destructive intent, mirroring techniques observed in large-scale cloud-based identity compromise incidents.
Detects scenarios where a user registers a new WebAuthn/Passkey credential and subsequently performs a sign-in from a different network or device shortly after, preceded by a sign-in from a risky or non-passkey-based method. This pattern is often associated with credential abuse or MFA registration hijacking.
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.


