Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
Page 326 of 1871
