Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potential DLL side-loading activity by identifying when known malicious file hashes are loaded by a specific set of executable files that are commonly abused for side-loading, or when these executables are executed from locations outside of their standard, verified installation directories.
This rule monitors network connection logs, DNS query logs, and common security logs for known indicators of compromise, specifically IP addresses and domains associated with command and control (C2) infrastructure.
This rule detects potential credential dumping attempts targeting the Local Security Authority Subsystem Service (LSASS) process. It identifies suspicious file execution based on a blocklist of known credential dumping utility hashes, unauthorized OpenProcess calls to lsass.exe with specific access rights, and the creation of process memory dump files (e.g., .dmp, .dump) correlated with an lsass.exe access event.
Detects indicators of the FamousSparrow threat actor, including the creation of known malicious files (e.g., DotNetNuke.ashx, start.bat), unauthorized .ashx file writes in web application directories, and suspicious command execution chains (start.bat execution or w3wp.exe spawning command-line utilities) following the creation of .ashx files.
Detects the execution of command-line tools (powershell, cmd, bash, curl, etc.) originating from common package managers and build tools (npm, node, pip, python, yarn). The rule flags these processes if they contain command-line arguments indicative of suspicious activity such as base64-encoded commands, remote script execution (IEX, curl/wget to shell), or indicators of persistence mechanisms (scheduled tasks, registry Run keys).
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
Detects the use of the native Windows utility 'wbadmin.exe' to delete the system backup catalog or system state backups. This activity is a common indicator of ransomware or other destructive attacks aiming to inhibit system recovery by preventing administrators from restoring data from existing backups.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
This KQL detects potential social engineering and vishing activity in Microsoft Teams over the last 30 days.
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
Remote Service Creation via SVCCTL RPC
Cortex XDR
Detects remote service manipulation, including service creation, starting, and deletion, using the SVCCTL RPC interface. This activity is a common method for lateral movement and remote code execution by tools like PsExec, smbexec, and CrackMapExec.
This rule detects potentially suspicious file deletion activity originating from PowerShell processes (powershell.exe or pwsh.exe). It monitors for commands targeting temporary directories and specific file extensions (such as .vbs, .lnk, .js, or .ps1) combined with recursive deletion arguments. Additionally, it highlights scenarios where these PowerShell commands are executed by potentially unusual parent processes such as script engines (wscript.exe, cscript.exe, mshta.exe) or other command-line utilities.
Detects high-frequency file creation, opening, or modification events within the Windows AppData Local Temp directory. This behavior, often involving specific obfuscated file names or known malicious process names, is a common indicator of malware payload staging or execution patterns, such as those observed in AsyncRAT infections.
Detects the execution of the Windows Character Map utility (charmap.exe) when launched from a user-writable Temp directory by a non-standard parent process. This pattern is commonly associated with malware, such as AsyncRAT, attempting to leverage legitimate system tools to evade detection or facilitate malicious chains.
Detects instances where the Windows Character Map utility (charmap.exe) loads both 'amsi.dll' (Antimalware Scan Interface) and 'clr.dll' (Common Language Runtime). This combination is highly anomalous for charmap.exe and is indicative of process injection or defense evasion attempts, often associated with executing arbitrary malicious code within a trusted system process.
Page 319 of 1871







