Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects network connections originating from browser processes to known JeetBot command and control (C2) infrastructure. The rule identifies suspicious C2 communication and, specifically, attempts at token exfiltration by monitoring for auth tokens in the URL of requests directed to known JeetBot hosts and Twitch-related infrastructure.
This rule identifies browser extensions installed on devices that are either explicitly known as malicious or exhibit suspicious naming patterns potentially associated with unauthorized or malicious extensions.
This rule identifies browser extensions installed on devices that are either explicitly known as malicious or exhibit suspicious naming patterns potentially associated with unauthorized or malicious extensions.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
This rule monitors for indicators of compromise (IOCs) associated with a specific AutoIT-based malware delivery chain. It tracks the execution and presence of specific malicious file names and SHA256 hashes, as well as network connections to a identified command-and-control (C2) infrastructure IP address (158.51.122.136). The detection spans file creation, process execution, image loading, and network communication events to identify the multi-stage attack lifecycle.
This rule detects references to specific social media handles and identifiers associated with the MEK/NCRI (National Council of Resistance of Iran) influence campaign within email URLs, device process command lines, and miscellaneous device events. It is designed to identify potential engagement with or dissemination of influence-related content on endpoints and in email communication.
This rule detects potentially malicious activity where multiple critical processes (such as database engines or email clients) are terminated in a short time frame, correlated with a high volume of file creation or modification events on the same device. This behavior is indicative of destructive activity, such as ransomware encrypting data stores or disabling defensive software.
Detects Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) that use RC4 encryption (0x17). In modern Active Directory environments, RC4 is considered weak and is often explicitly requested by attackers during Kerberoasting to facilitate offline brute-force cracking of service account passwords. The rule excludes common service accounts (e.g., krbtgt, machine accounts) to reduce noise.
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
Identifies instances of Google Chrome running on endpoints with version numbers below the threshold patched for CVE-2026-85046. This detection focuses on specific build numbers (e.g., 152.0.7977.82 for Windows/Linux) to identify potentially vulnerable browser installations in the environment.
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
Page 332 of 1871



