Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects HTTP POST requests to Vercel-hosted domains containing suspected phishing telemetry (such as device fingerprinting, keystrokes, and user agent collection) originated from a Google Sites frame. This is a common pattern for phishing kits masquerading as legitimate Ledger service pages to harvest credentials and hardware information.
This rule detects unauthorized attempts to extract credentials from the Local Security Authority Subsystem Service (LSASS) process. It monitors for two distinct techniques: non-standard processes opening handles to lsass.exe with sensitive access rights (credential-dumping) and the use of rundll32.exe to invoke the MiniDump function within comsvcs.dll against lsass.exe.
This rule detects HTTP traffic where a response from a Google Cloud Storage bucket (storage.googleapis.com) initiates a redirect via meta-refresh or JavaScript to a Vercel-hosted domain. This pattern is indicative of phishing infrastructure, where attackers leverage legitimate, trusted storage platforms to redirect users to malicious landing pages.
This rule detects HTTP traffic where a response from a Google Cloud Storage bucket (storage.googleapis.com) initiates a redirect via meta-refresh or JavaScript to a Vercel-hosted domain. This pattern is indicative of phishing infrastructure, where attackers leverage legitimate, trusted storage platforms to redirect users to malicious landing pages.
This rule detects HTTP traffic where a response from a Google Cloud Storage bucket (storage.googleapis.com) initiates a redirect via meta-refresh or JavaScript to a Vercel-hosted domain. This pattern is indicative of phishing infrastructure, where attackers leverage legitimate, trusted storage platforms to redirect users to malicious landing pages.
Detects directory replication requests (Event ID 4662) using DS-Replication-Get-Changes or DS-Replication-Get-Changes-All GUIDs initiated by a computer account that is not a recognized domain controller. This behavior is indicative of a DCSync attack, where an adversary attempts to pull sensitive credential data directly from Active Directory.
This rule detects HTTP traffic where a response from a Google Cloud Storage bucket (storage.googleapis.com) initiates a redirect via meta-refresh or JavaScript to a Vercel-hosted domain. This pattern is indicative of phishing infrastructure, where attackers leverage legitimate, trusted storage platforms to redirect users to malicious landing pages.
Detects the execution of the Chisel C2 tool by matching its unique command-line grammar, specifically the 'client' subcommand combined with reverse remote ('R:') configurations. This detection strategy is resilient against binary renaming and infrastructure rotation by focusing on the tool's required argument structure rather than static IOCs like filenames or C2 addresses. It is specifically useful for identifying unauthorized remote tunnels used for persistence and data exfiltration.
This rule identifies potential RDP-based lateral movement by detecting when a single user account successfully authenticates to multiple distinct hosts using LogonType 10 (RemoteInteractive) within a 1-hour time window. A threshold of three or more distinct hosts is used to flag activity that deviates from typical single-host RDP usage.
Detects the use of legitimate Windows binaries (LOLBins) certutil.exe and bitsadmin.exe for suspicious activities such as downloading files via URL or decoding encoded files. This rule explicitly excludes known legitimate administrative activity originating from Microsoft Configuration Manager (SCCM).
Detects the initialization of cloud synchronization tools like rclone or MEGAsync, accompanied by the creation of configuration files and subsequent high-volume network activity directed toward common cloud storage providers, indicative of unauthorized data exfiltration.
Detects successful user authentications originating from geographically distant locations within a time window that makes physical travel impossible. The detection further filters for scenarios where the subsequent sign-in is associated with a different, non-compliant, or untrusted device, indicating a likely compromised account.
This rule detects potential credential dumping from the Local Security Authority Subsystem Service (LSASS) memory. It identifies two common techniques: 1) The use of the Windows 'comsvcs.dll' library exported via 'rundll32.exe' to initiate a minidump of the LSASS process, and 2) Unauthorized processes opening handles to LSASS with specific access rights (0x1010, 0x1410) often associated with memory reading for dumping purposes.
Detects potential password spraying activity by identifying high-volume failed authentication attempts (ResultType 50126 or 50053) against multiple accounts from a single source IP, followed by a successful authentication from the same IP. This pattern indicates an adversary who has identified one or more valid credentials after an initial spraying campaign.
Detects successful user sign-ins from geographically distant locations occurring within a timeframe that is physically impossible to traverse (implied speed > 900 km/h). The rule further filters for scenarios where the device used for authentication appears non-compliant or uses an unrecognized method, potentially indicating an attacker utilizing stolen credentials and bypassing MFA.
Detects rapid, large-scale deletion of Azure storage accounts by a single identity within a short timeframe. This behavior is indicative of destructive activity, such as a malicious actor attempting to disrupt service availability or impact organizational data, rather than typical administrative teardown.
Detects rapid, large-scale deletion of Azure storage accounts by a single identity within a short timeframe. This behavior is indicative of destructive activity, such as a malicious actor attempting to disrupt service availability or impact organizational data, rather than typical administrative teardown.
Detects rapid, large-scale deletion of Azure storage accounts by a single identity within a short timeframe. This behavior is indicative of destructive activity, such as a malicious actor attempting to disrupt service availability or impact organizational data, rather than typical administrative teardown.
Detects rapid, large-scale deletion of Azure storage accounts by a single identity within a short timeframe. This behavior is indicative of destructive activity, such as a malicious actor attempting to disrupt service availability or impact organizational data, rather than typical administrative teardown.
Detects a suspicious sequence of behavior where an Azure service principal authenticates and immediately performs broad reconnaissance (enumeration) across multiple subscriptions and resource types. This pattern is often indicative of an adversary using a compromised service principal credential to map out an environment.
Detects a suspicious sequence of behavior where an Azure service principal authenticates and immediately performs broad reconnaissance (enumeration) across multiple subscriptions and resource types. This pattern is often indicative of an adversary using a compromised service principal credential to map out an environment.


