Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors for file creation or modification events related to the Admin Menu Editor Pro WordPress plugin, specifically looking for indicators of specific versions (2.35, 2.36) or file naming conventions. It also alerts on network communication to the plugin's domain, which could indicate a compromise or the use of an unauthorized or modified plugin version that may be associated with known vulnerabilities.
Detects DNS resolution requests for the domain 'myaccount.microsoft.com', which is the Microsoft account management portal. This activity is often associated with legitimate user authentication or account configuration processes, but can be used as part of reconnaissance or credential-related activities.
Detects individual process-level invocations of Microsoft Graph API endpoints commonly used for reconnaissance of user, group, and role information. This rule acts as a precursor signal to identify potential enumeration activities within an Office 365 environment.
Detects DNS resolution attempts for graph.microsoft.com by processes other than standard web browsers or mail clients. This activity is indicative of scripted tools or malicious software attempting to enumerate or access Microsoft 365 mailbox content via the Graph API, bypassing normal user interaction.
Detects the creation or modification of a scheduled task named 'Maps Performance Task' using schtasks.exe or reg.exe. This task is often associated with legitimate Windows system maintenance related to map data but may be monitored as it involves persistence mechanisms.
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
This rule identifies critical or high-severity software vulnerabilities affecting devices tagged as part of a PCI-CDE (Payment Card Industry Cardholder Data Environment) scope. It summarizes the findings by CVE, severity level, count of affected devices, and specific assets involved, prioritizing remediation for PCI compliance.
Detects instances where processes associated with AutoIt scripting (e.g., AutoIt-based compiled executables or scripts) initiate suspicious API calls including CreateRemoteThread, OpenProcess, or generic ProcessInjection against known target binaries such as RegSvcs.exe or mobsync.exe. These binaries are frequently abused for proxy execution or living-off-the-land techniques to hide malicious activity.
Detects the creation of .lnk files in Windows startup folders combined with the execution of AutoIt automation scripts, a technique commonly used for persistence and malware execution.
This rule detects the creation of files within the '\Users\Public\' directory that follow a specific, suspicious dynamic naming pattern: 'DeviceName@4AccountName'. Attackers often use the Public directory for staging malicious tools or payloads. This naming convention, which includes both the hostname and the executing account name, is highly indicative of automated, malicious activity or custom staging scripts.
Detects suspicious PowerShell execution initiated by explorer.exe containing encoded commands, correlated with concurrent activity in the Windows RunMRU registry key or execution of rundll32.exe referencing 'WindowsUpdate.log'. This pattern is frequently used to mask malicious activity and maintain stealth during fileless execution or persistence operations.
This rule detects potential command and control (C2) beaconing activity associated with the Casbaneiro (Metamorfo) banking trojan. It looks for instances where a known suspicious process (RegSvcs.exe or mobsync.exe) performs network communication within 5 minutes of a web browser on the same device navigating to a targeted banking URL.
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to known JeetBot infrastructure domains and IP addresses. The rule specifically identifies potential exfiltration of Twitch OAuth tokens via URL parameters or interaction with known token-collection proxy endpoints, which are associated with the JeetBot/Twitch Enhanced Viewer credential harvesting campaign.
Detects network connections to known JeetBot infrastructure domains and IP addresses. The rule specifically identifies potential exfiltration of Twitch OAuth tokens via URL parameters or interaction with known token-collection proxy endpoints, which are associated with the JeetBot/Twitch Enhanced Viewer credential harvesting campaign.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections originating from browser processes to known JeetBot command and control (C2) infrastructure. The rule identifies suspicious C2 communication and, specifically, attempts at token exfiltration by monitoring for auth tokens in the URL of requests directed to known JeetBot hosts and Twitch-related infrastructure.
Page 331 of 1871




