Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the loading or installation of a driver file identified as DCRCVDrv.sys followed within 5 minutes by EDR sensor heartbeat loss or process activity, which is characteristic of attempts to tamper with security software or hide malicious activity via a kernel-mode driver.
Detects process execution patterns and DNS requests associated with the GHAPPIER malware staging infrastructure. The rule monitors for specific command-line arguments involving known malicious scripts, temporary files, and deployment infrastructure (e.g., Vercel) often used for delivering or executing malicious payloads via node.js environments.
Detects a process that deletes its own executable file immediately after launching. This anti-forensic behavior is commonly utilized by remote access trojans (RATs) and other malware to minimize their footprint and evade file-based forensic analysis.
Detects network activity associated with NetSupport Manager remote access software, specifically targeting DNS lookups, TLS SNI connections, and direct TCP beaconing to a known-malicious infrastructure IP. This rule is designed to identify unauthorized use of legitimate remote support tools for command and control purposes.
Detects malicious JavaScript/npm payloads that attempt to evade static analysis and string-based detection signatures by dynamically reconstructing sensitive strings at runtime using V8 string-object construction or obfuscated string tables.
Detects execution of code using indirect syscalls or ntdll unhooking techniques, often associated with the PIVOTPIPE loader/RAT. The rule monitors for EDR indicators of evasion such as syscall stub execution, direct/indirect Nt* system call invocation, or call stacks originating outside of ntdll.dll, intended to bypass userland security hooks.
Correlates an MFA method change with the next sign-in occurring from an ASN/country never seen for that user in 30 days, operationalizing TrustSphere's 2026 finding that reset-then-new-location access is the clearest signal separating a hijack from a genuine recovery.
This rule detects modifications to GitHub Actions workflow configuration files (.yml or .yaml) located in the .github/workflows/ directory. Such modifications may indicate unauthorized tampering with CI/CD pipelines to facilitate persistent execution, credential theft, or supply chain attacks.
Aggregates MFA/passkey enrollments tenant-wide, alerting when an unusual number of distinct users register new authenticators within a short rolling window — a mass-takeover indicator rather than isolated recovery activity, especially when linked by a common actor or source ASN.
Flags changes to a user's registered SMS/voice MFA phone number followed by a successful high-risk sign-in — the SIM-swap/SMS-interception bypass step documented across the 2024-2026 vishing threat-report taxonomy (CrowdStrike, Mandiant, Pindrop).
Detects attempts to bypass macOS Gatekeeper security controls by manually removing the 'com.apple.quarantine' extended attribute using 'xattr' or by modifying executable permissions with 'chmod' on specific system or sensitive file paths, such as 'iSync'. These actions are commonly performed to evade execution restrictions on downloaded or untrusted files.
Detects Node.js processes executing suspicious command lines that involve fetching and executing remote JavaScript code. This behavior is indicative of a loader or downloader script commonly used to pull and evaluate malicious payloads at runtime, specifically referencing indicators associated with 'GHAPPIER'.
Detects the reuse of a session or refresh token from a geographic location that contradicts recent user activity (impossible travel) without a new interactive MFA challenge. This activity is indicative of Adversary-in-the-Middle (AiTM) phishing attacks, such as those leveraging Evilginx, where session cookies are captured and replayed from attacker infrastructure to bypass multi-factor authentication.
Detects when a user adds a new Multi-Factor Authentication (MFA) method such as a phone number, authenticator app, or FIDO2 key in Entra ID (Azure AD). Attackers often register their own MFA devices to maintain persistent access to a compromised account, particularly following a successful password reset or social engineering event.
Detects the Cursor IDE application launching specific macOS system binaries ('SystemUpdate', 'iSync', 'loginwindow') that are potentially being used to execute hidden backdoors, often associated with the 'FLATROOF' or 'ROOFDECK' threats. The rule looks for process spawning behavior where Cursor initiates these binaries with specific suspicious command-line flags ('nohup', '--type=renderer') or in directories associated with known malicious activity.
Detects instances where npm processes (install, preinstall, or postinstall) spawn suspicious child processes such as shell interpreters (cmd, powershell, bash, sh), network utilities (curl, wget), or scripting interpreters (python). This behavior is often associated with malicious npm package installation or software supply chain compromise where post-install scripts are used to gain persistence or download secondary payloads.
Detects the execution of PowerShell with hidden window arguments from explorer.exe, typically indicative of ClickFix social engineering where a user is tricked into pasting malicious commands into the Windows Run dialog.
Detects the creation of mailbox inbox rules (New-InboxRule) or modification of mailbox forwarding configurations (Set-Mailbox) that auto-forward, auto-delete, or move messages to hidden or secondary folders (e.g., RSS, Deleted Items). This behavior is characteristic of Business Email Compromise (BEC) follow-on activity intended to maintain covert access to victim communications, particularly following account takeover events like password resets.
Detects a suspicious pattern where an inbound Microsoft Teams call or chat from an untrusted external guest tenant is followed within 30 minutes by a credential, MFA, or account-recovery action on the target user's account in Entra ID. This behavior is indicative of a vishing-over-Teams attack where an adversary impersonates IT support to facilitate unauthorized account recovery or MFA bypass.
Detects instances where processes (excluding known legitimate .NET processes) load common .NET runtime modules (e.g., clr.dll, mscoree.dll) followed by remote process injection or handle-based process access, which is often indicative of reflective assembly loading used by loaders like PIVOTPIPE to execute malicious code within a target process.
Detects a suspicious sequence of events where a user modifies their MFA phone number, followed within 30 minutes by a sign-in event flagged with 'impossibleTravel' or 'unfamiliarFeatures' risk. This pattern is indicative of potential SIM-swap fraud, where an attacker has hijacked the user's phone number to receive MFA prompts and then attempts to access the account from an anomalous location.
