Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects the execution of known malicious MSI files associated with the LegionLoader malware family by monitoring process creation events involving msiexec.exe. The rule matches on specific file hashes and filenames identified in technical analysis of LegionLoader variants.
Detects the loading of a known malicious 7z.dll file within the 'Traiolx Custom Utils' directory. This behavior is indicative of DLL sideloading used by LegionLoader to achieve code execution under the guise of a legitimate application.
Detects the loading of a known malicious 7z.dll file within the 'Traiolx Custom Utils' directory. This behavior is indicative of DLL sideloading used by LegionLoader to achieve code execution under the guise of a legitimate application.
Detects the presence of a suspicious or known malicious 'Normaliz.dll' file located within the 'Traiolx Custom Utils' directory, indicative of a DLL sideloading attempt.
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This behavior is often associated with malware or malicious loaders (such as LegionLoader) that use secondary instances to facilitate malicious code execution or persistence while masquerading as legitimate update utilities.
Detects the installation or registration of the legitimate gitlab-runner.exe binary as a persistent Windows service. Adversaries can leverage this technique to establish a command-and-control (C2) channel or persistent backdoor by masquerading as legitimate CI/CD infrastructure.
Detects unsigned or non-standard Python processes loading core Windows system modules like kernel32.dll or ntdll.dll. This behavior is consistent with NarwhalRAT's fileless execution technique, which utilizes ctypes to interact with low-level Windows APIs (VirtualAlloc, RtlMoveMemory, CFUNCTYPE) for in-memory payload allocation and execution, bypassing traditional disk-based detection.
Detects the BTR.sys driver, a tool identified as being extracted from Microsoft's MpEngine.dll and repurposed for kernel-level file and registry manipulation. The rule matches on specific SHA-256 file hashes or combinations of PE metadata strings, indicating the presence of this driver on the system.
This rule detects the creation of a new service in HKLM\SYSTEM\CurrentControlSet\Services that includes specific suspicious command-line arguments (containing ':changelist') and is configured to start automatically (Start value '1') or belongs to the 'Boot Bus Extender' group. This behavior is often associated with persistence mechanisms where adversaries register a service to execute malicious payloads upon system startup.
Detects repeated large HTTP PUT or POST requests (exceeding 5MB) from a internal host to external destinations. This pattern is indicative of potential bulk data exfiltration over web services.
Detects the execution of BTR_CLI.exe with command line arguments indicative of installing or interacting with the Mimikatz driver (mimidrv.sys). This behavior is associated with loading the malicious driver to facilitate credential dumping from kernel memory.
Detects the creation of .bat files within the Windows Startup folder. Adversaries often use this technique to achieve persistence by ensuring a script executes automatically upon user login.
Detects the execution of PowerShell with suspicious command-line flags often associated with malicious scripts (e.g., hidden windows, no profile, bypassed execution policies) when the script is located in the Windows Temporary directory.
Detects instances of the Windows Character Map utility (charmap.exe) loading graphics-related libraries such as System.Drawing.dll or gdiplus.dll. These modules are typically not required by charmap.exe and their loading is a common indicator of process injection for the purpose of capturing the screen or desktop interface.
Detects instances where PowerShell is launched as a child process of WScript.exe or CScript.exe with suspicious command line flags intended to hide window visibility, bypass execution policies, or run in a non-interactive mode. This behavior is frequently used by adversaries to execute obfuscated or malicious scripts while minimizing user awareness.
Detects instances where PowerShell.exe spawns the .NET C# compiler (csc.exe) with command-line arguments referencing a '.cmdline' file. This pattern is commonly used by adversaries to compile malicious code in-memory, bypassing traditional disk-based file scanning.

