Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation of mailbox inbox rules (New-InboxRule) or modification of mailbox forwarding configurations (Set-Mailbox) that auto-forward, auto-delete, or move messages to hidden or secondary folders (e.g., RSS, Deleted Items). This behavior is characteristic of Business Email Compromise (BEC) follow-on activity intended to maintain covert access to victim communications, particularly following account takeover events like password resets.
Detects a suspicious pattern where an inbound Microsoft Teams call or chat from an untrusted external guest tenant is followed within 30 minutes by a credential, MFA, or account-recovery action on the target user's account in Entra ID. This behavior is indicative of a vishing-over-Teams attack where an adversary impersonates IT support to facilitate unauthorized account recovery or MFA bypass.
Detects instances where processes (excluding known legitimate .NET processes) load common .NET runtime modules (e.g., clr.dll, mscoree.dll) followed by remote process injection or handle-based process access, which is often indicative of reflective assembly loading used by loaders like PIVOTPIPE to execute malicious code within a target process.
Detects a suspicious sequence of events where a user modifies their MFA phone number, followed within 30 minutes by a sign-in event flagged with 'impossibleTravel' or 'unfamiliarFeatures' risk. This pattern is indicative of potential SIM-swap fraud, where an attacker has hijacked the user's phone number to receive MFA prompts and then attempts to access the account from an anomalous location.
This rule monitors for network DNS queries containing keywords commonly associated with credential harvesting and identity verification lures, such as 'sso', 'mfa', 'passkey', or 'helpdesk'. It detects attempts to reach suspicious domains that may be used in phishing campaigns targeting corporate identity portals.
Detects a Node.js server process (e.g. "next-server", "node.exe") spawning
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
This rule detects unauthorized attempts to perform a DCSync attack by monitoring for Active Directory Event ID 4662. It triggers when an account that is not a recognized domain controller (which typically end with a '$' sign) successfully requests replication data using the Directory Replication Service (DRS) GetNCChanges rights. This behavior is a common indicator of credential dumping via tools like Mimikatz.
Detects the execution of known privilege escalation tools and the use of specific Windows privilege keywords (such as SeImpersonatePrivilege) often associated with access token manipulation and token impersonation attacks to elevate privileges to SYSTEM.
Detects anomalous DNS traffic patterns indicative of command-and-control (C2) or data exfiltration over the DNS protocol. The rule identifies suspicious queries containing long, high-entropy subdomain labels that suggest payload encoding, as well as the use of TXT records for unauthorized data transmission.
Detects attempts to disable Windows Defender features via PowerShell, terminate critical security services using administrative tools like sc.exe or net.exe, or inject/patch AMSI (Antimalware Scan Interface) within a process context to evade detection.
Detects outbound web or proxy connections to known consumer-grade cloud storage and file-sharing services. This activity is often indicative of data exfiltration, where an adversary uploads staged or archived sensitive data to third-party file hosting services (e.g., Mega, Dropbox, transfer.sh, pastebin) to bypass traditional enterprise exfiltration controls.
This rule detects potentially suspicious activity within a Git repository environment, specifically monitoring for code pushes, administrative changes (such as added collaborators, permission changes, or ownership transfers), and force push operations. It identifies high-impact repository modifications that could indicate unauthorized access, persistence, or attempts to disrupt repository integrity.
This rule detects Terraform CLI activity interacting with suspicious domains or modules, specifically targeting known repositories or namespaces (e.g., gocommunity.io, gogets.dev). It monitors for Terraform initialization or application patterns referencing these domains in process command lines, as well as the creation of Terraform provider files within these specific namespaces. This behavior is indicative of potential supply chain compromise involving malicious Terraform modules or dependencies.
Detects the execution of 'go' or 'go.exe' with 'run' commands originating from infrastructure automation or orchestration tools such as Terraform, Docker, or other related automation processes. This pattern may indicate the execution of arbitrary Go code or modules in environments where infrastructure code is being managed or deployed.
Detects a single developer identity performing a high volume of git push or clone operations across a large number of distinct repositories within a short timeframe. This behavior is indicative of a compromised developer account being used to programmatically inject code into multiple repositories, potentially for a supply chain attack or mass payload propagation.
Detects the execution of terraform.exe or go.exe on developer hosts, which acts as a precursor to the malicious Terraform provider campaign (Graphalgo) that targets cloud credentials.
Detects suspicious activities associated with ysoserial.net gadget chain exploitation targeting SharePoint's w3wp.exe process. The rule correlates the loading of specific .NET assemblies (PresentationFramework, System.Xaml, System.Data.Services) with the subsequent execution of command shells (cmd, powershell) or the presence of common ysoserial.net-related strings (ActivitySurrogateSelector, LosFormatter) within command lines originating from the w3wp.exe process, indicating a potential web shell.
Detects the execution of the Graphalgo RAT second-stage payload. The rule identifies the spawning of a detached 'go run .' process, which performs an ephemeral key exchange using a hardcoded public key before C2 establishment. It also correlates this activity with parent processes common in software build environments (npm, terraform, go) to differentiate malicious staging from developer activity.



