Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
This rule detects modifications to Group Policy Objects (GPO) or Microsoft Entra (formerly Azure AD) policies that weaken established security controls. For GPO, it monitors Event ID 5136 for changes to security-relevant attributes (e.g., disabling firewall or real-time monitoring) in Active Directory. For Entra, it monitors audit logs for administrative operations that reduce security posture, such as disabling MFA, lowering authentication trust, or deleting Conditional Access policies. It includes filters to exclude legitimate, documented change management activities.
Detects Run key persistence pointing to the known VBScript staging directory (C:\Users\Public\Libraries\Default\Lib\Lib1) used by the worm-like ScreenConnect campaign (Aug 2026), matching known script filenames (WindowsServiceHost.vbs, 1.vbs-4.vbs) invoked via wscript.exe/cscript.exe.
Detects suspicious PowerShell execution initiated by explorer.exe containing encoded commands, correlated with concurrent activity in the Windows RunMRU registry key or execution of rundll32.exe referencing 'WindowsUpdate.log'. This pattern is frequently used to mask malicious activity and maintain stealth during fileless execution or persistence operations.
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
Detects the execution of known malicious files associated with the BlueDelta threat group, specifically the HOOKEDGE and HEADLACE malware families, using a curated list of SHA-256 file hashes. Additionally, the rule monitors for the execution of scripts with GUID-based filenames, a common tactic for temporal or staged file deployment.
Matches known HOOKEDGE malware samples attributed to BlueDelta (APT28) via SHA256 hash comparison
Matches known HOOKEDGE malware samples attributed to BlueDelta (APT28) via SHA256 hash comparison
Detects network communication with Google Sheets API endpoints that contain specific indicators of C2 behavior, such as suspicious User-Agents, specific spreadsheet cell references, or input options characteristic of automated data exfiltration or command retrieval.
This rule monitors for outbound network connections to a list of known malicious IP addresses identified as part of the GhostCode command-and-control (C2) infrastructure. It uses DeviceNetworkEvents data to flag activity originating from endpoints and highlights a specific IP address used during the Intune/MDM enrollment process for further investigation.
Detects network activity and HTTP request headers associated with the GhostCode phishing kit. The rule identifies specific URI patterns, custom site keys, malicious User-Agent strings, and session cookie artifacts indicative of interaction with a phishing server.
Detects instances of ImageMagick binaries (convert, identify, magick) spawning suspicious child processes (e.g., shells, network tools, scripting interpreters) when processing image files with HEIF/HEIC extensions. This is a common pattern for exploiting image processing vulnerabilities (e.g., ImageTragick) to achieve remote code execution.
Detects instances of ImageMagick binaries (convert, identify, magick) spawning suspicious child processes (e.g., shells, network tools, scripting interpreters) when processing image files with HEIF/HEIC extensions. This is a common pattern for exploiting image processing vulnerabilities (e.g., ImageTragick) to achieve remote code execution.
Detects instances of ImageMagick binaries (convert, identify, magick) spawning suspicious child processes (e.g., shells, network tools, scripting interpreters) when processing image files with HEIF/HEIC extensions. This is a common pattern for exploiting image processing vulnerabilities (e.g., ImageTragick) to achieve remote code execution.
Detects instances of ImageMagick binaries (convert, identify, magick) spawning suspicious child processes (e.g., shells, network tools, scripting interpreters) when processing image files with HEIF/HEIC extensions. This is a common pattern for exploiting image processing vulnerabilities (e.g., ImageTragick) to achieve remote code execution.
Page 323 of 1871


