Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects a high volume of unique command executions within a short time window where the command lines contain patterns resembling developer or script comments (e.g., # or // followed by keywords like 'attempt', 'retry', 'diagnos'). The threshold-based logic (over 600 unique commands in less than 1 hour) combined with high-frequency retry attempts suggests automated or scripted activity, potentially indicative of automated exploitation frameworks, reconnaissance, or brute-force tools that include verbose logging or internal notes within the command execution.
Detects the use of the Rubeus tool for Kerberos-based credential attacks, specifically Kerberoasting, TGT delegation abuse, and Pass the Ticket, by monitoring process command line arguments for characteristic flags associated with the Rubeus binary.
Detects a suspicious correlation where a host reports a confirmed exploit attempt followed by a high volume of file modifications (encryption behavior) within a single hour. This short dwell time is a strong indicator of automated or AI-orchestrated ransomware deployments.
Detects unauthorized directory replication requests (DRSGetNCChanges or DRSReplicaSync) originating from a host that is not identified as a Domain Controller. This behavior is indicative of a DCSync attack, where an adversary impersonates a domain controller to extract credential hashes from the Active Directory database.
Detects command-line activity associated with Monkey ransomware, specifically attempts to bypass AMSI (patching AmsiScanBuffer, targeting AmsiUtils), disable ETW (Event Tracing for Windows) monitoring, and add Microsoft Defender exclusions to evade detection prior to encryption.
Detects the creation of a 'config.ini' file within the 'UBP-Asset' directory, correlated with subsequent FTP network activity from known associated binaries (UBPUpdater.exe, UBPPatch.Psh, cmd.exe, or UBP.exe). This behavioral pattern is indicative of Quasar RAT being delivered or updated through a fraudulent install path.
Detects the creation of a 'config.ini' file within the 'UBP-Asset' directory, correlated with subsequent FTP network activity from known associated binaries (UBPUpdater.exe, UBPPatch.Psh, cmd.exe, or UBP.exe). This behavioral pattern is indicative of Quasar RAT being delivered or updated through a fraudulent install path.
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
This rule detects potential ransomware activity by monitoring for a high volume (more than 10) of file creation or renaming events within a short timeframe (30 minutes) initiated by a process named 'htspnew.exe'. It excludes common system and temporary directories to reduce noise, focusing on suspicious file modifications that might indicate bulk encryption or mass file manipulation.
This rule detects potential ransomware activity by monitoring for a high volume (more than 10) of file creation or renaming events within a short timeframe (30 minutes) initiated by a process named 'htspnew.exe'. It excludes common system and temporary directories to reduce noise, focusing on suspicious file modifications that might indicate bulk encryption or mass file manipulation.
This rule detects potential ransomware activity by monitoring for a high volume (more than 10) of file creation or renaming events within a short timeframe (30 minutes) initiated by a process named 'htspnew.exe'. It excludes common system and temporary directories to reduce noise, focusing on suspicious file modifications that might indicate bulk encryption or mass file manipulation.
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
Detects the execution of common Windows command-line tools (such as cmd, powershell, or wmic) being used to query system information related to security configurations, antivirus status, firewall status, or installed security products. This behavior is indicative of an adversary performing reconnaissance to understand the defensive landscape of a compromised host.
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
Detects the execution of AutoIt3 scripts using mshta.exe as the parent process from suspicious or non-standard directories such as Temp, Downloads, or AppData. This behavior is indicative of an attempt to bypass application execution policies or obfuscate malicious script execution.
Detects the execution of AutoIt3 scripts using mshta.exe as the parent process from suspicious or non-standard directories such as Temp, Downloads, or AppData. This behavior is indicative of an attempt to bypass application execution policies or obfuscate malicious script execution.
Detects the execution of AutoIt3 scripts using mshta.exe as the parent process from suspicious or non-standard directories such as Temp, Downloads, or AppData. This behavior is indicative of an attempt to bypass application execution policies or obfuscate malicious script execution.
Page 314 of 1871


