Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects the execution of the MeshAgent remote administration tool from a temporary directory followed by a network connection to known malicious infrastructure within a 15-minute window. This behavior is indicative of unauthorized remote access setup or C2 activity using a legitimate remote management utility.
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
Detects network traffic associated with the NPM Btree malware campaign, specifically identifying command-and-control (C2) polling activities directed toward blockchain RPC endpoints like Alchemy and Infura. The rules monitor for specific API keys, C2 smart contract addresses via 'eth_call' JSON-RPC requests, and overall traffic patterns to known malicious infrastructure.
Detects Microsoft 365 Exchange MailItemsAccessed operations performed by a specific ClientAppId and AppId known to be associated with an exfiltration toolkit. This activity indicates unauthorized access to mail items, consistent with data harvesting efforts.
Detects high-volume file access or download operations in SharePoint or OneDrive performed by common scripting libraries and client user agents, which may indicate automated data exfiltration.
Detects Node.js processes executing system-level reconnaissance (e.g., CPU, memory, hostname, uptime enumeration) followed by network connections to known exfiltration endpoints (Slack, Telegram API). This behavior aligns with identified npm malware campaigns using host fingerprinting for target selection and data exfiltration.
Detects the execution of the Windows Workspaces Broker process (wkspbroker.exe) when it loads a library (DLL) from a path within the RemoteApp Gateway directory under LOCALAPPDATA. This behavior is associated with DLL side-loading techniques used to execute malicious payloads such as the Xray-core implant.

