Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
Detects the use of PowerShell cmdlets such as Invoke-WmiMethod, Invoke-CimMethod, Get-CimInstance, or Get-WmiObject to interact with the Win32_Process class for process creation on local or remote systems. This behavior is frequently associated with administrative activity but is also commonly used by adversaries for remote command execution and lateral movement.
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
Detects the use of Dumpert process dumper, which dumps the lsass.exe process memory
Detects the execution of batch files named 'db.bat' or 'adb.bat' from the Windows User Temp directory using cmd.exe. This activity is a known indicator of the OpnKey ransomware, which utilizes these scripts to facilitate its operations.
Detects the use of net.exe to stop critical system services commonly associated with ransomware operations, such as volume shadow copies, security services, and Windows update services, to facilitate data encryption or prevent system recovery.
Detects the use of the Windows schtasks utility to delete a scheduled task named 'Windows Update'. This pattern is associated with OpnKey ransomware, which attempts to remove legitimate or potentially competing tasks to maintain persistence or avoid detection.
Detects the deletion of a file named 'Config.ini', a behavior associated with the OpnKey ransomware for cleaning up configuration artifacts after its execution cycle.
Detects the presence of OpnKey ransomware-specific configuration strings related to size-tiered file encryption settings in process command lines. These indicators suggest the execution of a binary with hardcoded logic to categorize files for encryption based on their size.
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
SAMR User and Domain Enumeration via RPC
Cortex XDR
Detects high-volume usage of SAMR RPC functions (SamrEnumerateUsersInDomain, SamrLookupNamesInDomain, SamrQueryInformationUser) used to enumerate domain users and account attributes. This behavior is indicative of reconnaissance activities performed by tools such as secretsdump, BloodHound, and NetExec.
Page 334 of 1871




