Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of the Bun JavaScript runtime invoking 'index.js' as part of an npm lifecycle event (such as preinstall). This pattern is commonly used in supply chain attacks to execute arbitrary code during the installation of malicious packages.
Detects the execution of the Bun JavaScript runtime invoking 'index.js' as part of an npm lifecycle event (such as preinstall). This pattern is commonly used in supply chain attacks to execute arbitrary code during the installation of malicious packages.
Detects browser processes (Chrome or Firefox) originating from specific file paths or extension IDs attempting to perform OAuth validation against the Twitch API. This behavior is indicative of potentially malicious browser extensions or extensions masquerading as legitimate tools attempting to handle user authentication tokens.
Detects the installation or update of a browser extension that requests specific host permissions related to Twitch (gql.twitch.tv, usher.ttvnw.net, id.twitch.tv) combined with suspicious domains (jeetbot.cc, drisnya.online, morphilina.me, deno.dev, deno.net). This pattern is indicative of malicious browser extensions designed to intercept credentials or manipulate Twitch-related traffic.
Detects anomalous execution or network activity involving a 'content.js' file in conjunction with specific proxy-related artifacts or authorization headers. This pattern is indicative of a malicious browser extension or script attempting to intercept or proxy web traffic and credentials.
This rule detects either the execution of specific files identified by SHA256 hashes or the installation/enabling of browser extensions matching known malicious extension IDs. This monitoring helps identify the introduction of potentially harmful browser-based persistent threats or the presence of known malicious binaries on endpoints.
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
Detects network communication with identified C2 infrastructure associated with VectraRAT, Amadey, and ClickFix campaigns, as well as the presence of a specific 'callback.json' artifact in temporary directories, which is commonly used for C2 address overrides.
Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
This rule performs a hunting activity across multiple telemetry sources (Network, Email, Endpoint) to detect known indicators of compromise (IOCs) associated with Anthropic threat intelligence reporting (September 2026). It looks for specific malware file names, command-line patterns, service installations, phishing email addresses, and C2 communication URLs.
This rule detects the creation or modification of registry run keys associated with the JartePortable application. The detection logic looks for persistence mechanisms that point to executable paths in public directories or specific registry value data associated with known PlugX malware activity.
Detects Adobe Acrobat (Acrobat.exe) launched by a suspicious parent process (GRrte.exe) while opening a specific PDF document from the user's temporary directory. This pattern is indicative of a potential malicious document lure often associated with malware delivery.
Detects the execution of taskkill.exe to forcibly terminate the iediagcmd.exe diagnostic process, initiated by the process GRrte.exe. This behavior is indicative of an attempt to impair security or diagnostic tools on the endpoint.
MicroStealer is a newly emerging infostealer that spreads quickly, evades traditional detection, and focuses on stealing corporate credentials, browser data, session tokens, and cryptocurrency wallets. Its layered delivery chain (NSIS → Electron → Java) and heavy obfuscation make it difficult to detect, while exfiltration occurs via Discord webhooks and attacker‑controlled servers.
Page 329 of 1871




