Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects rapid mass-cloning or downloading of private GitHub repositories shortly after an OAuth token authorization, originating from IP addresses or countries not previously associated with the user account. This behavior is indicative of unauthorized bulk data extraction using compromised credentials, consistent with threat actor activity (e.g., TeamPCP/UNC6780).
Detects instances where a removed GitHub organization member performed bulk repository access (cloning or downloading) shortly before their removal, potentially indicating exploitation of retained access by a departed employee or an adversary using a valid account before deprovisioning. The rule identifies activity occurring more than 24 hours prior to removal involving multiple repositories or multiple access actions.
Detects the execution of PowerShell with suspicious command-line arguments often used by adversaries for obfuscation, evasion, or in-memory code execution, such as encoded commands, hidden windows, and downloading external content.
This rule detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos Service Ticket (TGS) requests (event ID 4769) for non-machine service accounts, specifically focusing on tickets encrypted with RC4 (etype 23). A high count of ticket requests or distinct Service Principal Names (SPNs) requested by a single client in a short period is characteristic of an adversary attempting to harvest hashes for offline cracking.
This rule detects the use of native Windows utilities certutil.exe and bitsadmin.exe for potentially malicious purposes. Specifically, it flags certutil.exe being used for decoding or cached URL operations, and bitsadmin.exe being used to initiate file transfers from remote URLs or network paths. These tools are commonly abused by attackers for file staging, ingress tool transfer, and deobfuscation of malicious payloads.
This rule detects the creation of named pipes with names patterns commonly associated with post-exploitation frameworks, such as Cobalt Strike and Sliver. These frameworks frequently use specific, sometimes randomized, pipe patterns for inter-process communication, lateral movement, or command and control (C2) operations. Monitoring these pipe names can help identify malicious activity occurring within a compromised environment.
Detects outbound HTTP requests to the Telegram Bot API associated with the malicious 'indexed-btree' npm package. The rule specifically monitors for hardcoded Telegram bot tokens and chat IDs used for data exfiltration.
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
KQL Query
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
Detects an account takeover chain where a device loads a malicious JavaScript component ('load-addon.js') in a browser session, followed by repeated attempts to bypass bot detection mechanisms (targeting Google's 'errors/robot.png') as the payload attempts to force authentication challenges or password resets.
Detects an account takeover chain where a device loads a malicious JavaScript component ('load-addon.js') in a browser session, followed by repeated attempts to bypass bot detection mechanisms (targeting Google's 'errors/robot.png') as the payload attempts to force authentication challenges or password resets.
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.


