Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
Detects high-volume deletion or recycling of files within OneDrive or SharePoint for a specific user, which may indicate malicious activity such as data destruction, ransomware, or unauthorized data exfiltration staging.
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
This rule detects command-line activity where a remote resource is downloaded via 'curl', decoded using 'base64', and then piped directly into a shell interpreter (sh, bash, or zsh). This pattern is commonly used in fileless execution or stage-one payload delivery by attackers to execute malicious scripts directly from memory.
Detects usage of the net1.exe utility to list members of the local 'Administrators' group in various languages. This technique is often used by adversaries for local system discovery during the reconnaissance phase.
Detects network traffic directed towards Telegram shortened URLs (t.me) which is a common command-and-control (C2) communication channel used by Vidar and other malware families to exfiltrate data or retrieve instructions.
Detects modifications to the WDigest 'UseLogonCredential' registry key. Enabling this setting (setting it to 1) forces the WDigest SSP to store plaintext credentials in memory, which facilitates easier credential harvesting by attackers using memory dumping techniques.
This rule detects potential web shells that employ steganographic techniques by embedding malicious executable script code within image file structures (JPG or PNG). It specifically flags files containing common web shell markers 'ONEPIECE' or 'x_best_911' in combination with embedded script tags (e.g., <script, eval, <%, <?php) within files identified as having image magic bytes.
Detects GitHub OAuth authorization, repository cloning, or ZIP downloads from source IP addresses that have not been observed for the specific actor within the past 30 days. This rule helps identify potential account compromise or token theft where an attacker attempts to access repository data from a new location, while specifically excluding bot/service accounts known for rotating CI infrastructure IPs.
Detects the creation or execution of a scheduled task named 'CreateObjectTask' via schtasks or PowerShell, which is associated with spawning 'dllhost.exe' as a child process under high-privileged parent processes (svchost, taskeng, or schtasks). This behavior is indicative of potential COM hijacking or privilege escalation techniques leveraging system tasks.
Detects the use of PowerShell to perform COM database enumeration, often associated with OleViewDotNet or NtObjectManager tools, specifically looking for indicators of COM object querying such as InProcServer32 path identification.
Detects web browser processes (e.g., Chrome, Edge, Firefox) spawned by parent processes that are not typical for web browser execution. This behavior is often associated with malware (such as infostealers) using unconventional process spawning to inject code or perform credential theft.
This rule detects the use of PowerShell cmdlets often associated with enumerating COM object registrations, specifically targeting 'InProcServer32' registry keys. Such enumeration is a common reconnaissance step for identifying 'dangling' COM objects—registrations that point to missing or non-existent files—which can be exploited to achieve DLL Hijacking or persistence via COM hijacking.
Detects the dllhost.exe process, running with SYSTEM privileges, loading a dynamic link library (DLL) from a user-writable path within the ProgramData directory. This behavior is consistent with the abuse of COM marshaling, specifically exploiting dangling CLSID entries to force a privileged COM host process to unmarshal and load an attacker-controlled DLL.
Detects JavaScript loaders associated with the Exvicy/ErrTraffic campaign. The rule identifies obfuscated code that utilizes atob() for Base64 decoding, single-byte XOR operations, TextDecoder for content processing, and dynamic code execution via 'new Function()'. This pattern is commonly used to inject malicious payloads into compromised WordPress sites.
Detects outbound HTTP requests to the Telegram Bot API (/sendMessage) which are often used by malware (such as 'Exvicy' or 'Small Sieve') for command and control or exfiltration notification, utilizing the Telegram bot token structure in the URI.
Detects a specific bot-cloaking technique used by the Exvicy/ErrTraffic framework, where an actor makes requests to bot-decision endpoints (index.php/white.php) while providing a spoofed 'google.com' Referer header to a non-Google destination host. This technique is often used to facilitate the delivery of fraudulent content (e.g., fake Turnstile/ClickFix pages) while evading detection by security scanners and undesired geographic regions.
Detects outbound network traffic from internal hosts directed toward identified Exvicy command-and-control (C2) infrastructure IP addresses. This includes both general beaconing attempts and established TLS handshake sessions potentially linked to post-ClickFix malicious activity.
Detects an attempt to exploit a directive injection vulnerability in the SharePoint 'WebPartPages.asmx' SOAP web service, specifically targeting the 'GetWebPartPageConnectionInfo' method. The rule looks for suspicious 'Register' directives in the request body, which could lead to unauthorized code execution or configuration manipulation.

