Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.

