Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
This rule detects the loading of specific drivers identified as potentially associated with security software evasion or 'Bring Your Own Vulnerable Driver' (BYOVD) tactics, followed by suspicious process termination activity (e.g., termination of security-related processes or system-critical process activity) within a 15-minute window on the same device.
Detects the creation or modification of specific system driver files (nvfsflt64.sys, Alinubx.sys) combined with the installation or initiation of a Windows service associated with NVIDIA filter names. This behavior is often indicative of persistence mechanisms, potential rootkit activity, or the deployment of vulnerable drivers (BYOVD).
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
Detects instances where sensitive Active Directory database files (NTDS.DIT) are accessed, correlated with the execution of common system administration utilities (ntdsutil, vssadmin, diskshadow, esentutl) known to be leveraged by adversaries to create volume shadow copies or extract data for offline credential harvesting.
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
Detects instances where Windows Filtering Platform (WFP) has blocked outbound network connections initiated by critical Microsoft Defender components (e.g., MsSense.exe, MsMpEng.exe). Such blocks may indicate security software interference, misconfiguration, or attempts to disrupt endpoint security monitoring.
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
Detects execution and file artifacts associated with the 'fscan' network scanning tool, which is commonly used for internal network discovery and vulnerability scanning. The rule monitors for the presence of the fscan binary or evidence of its output files, specifically 'result.txt', often in combination with scanning parameters like port strings or target service references.
Detects execution and file artifacts associated with the 'fscan' network scanning tool, which is commonly used for internal network discovery and vulnerability scanning. The rule monitors for the presence of the fscan binary or evidence of its output files, specifically 'result.txt', often in combination with scanning parameters like port strings or target service references.
Detects the execution of Python scripts named 'exploit.py' or 'exp.py', which are common naming conventions associated with proof-of-concept or exploit code.
This rule detects potential exploitation activities targeting Atlassian Confluence by monitoring for unauthorized access to administrative configuration actions (e.g., setup/setupadministrator.action) and the subsequent addition of accounts to the 'confluence-administrators' group. It correlates process execution, network request patterns, and local user account modifications to identify successful or attempted privilege escalation and configuration manipulation.
Detects an authentication event followed by a computer account change event (Event ID 4742) targeting a domain controller computer account. This pattern may indicate unauthorized modifications to domain controller machine accounts, which is often associated with persistence or privilege escalation attempts.
Detects network communication originating from the 1C:Enterprise server process (rphost.exe) to a specific remote IP address and port associated with potential malicious activity.
Detects outbound network connections made by 1C Enterprise processes (rmngr.exe or rphost.exe) to non-private/external IP addresses over specific ports (1541, 1570, 1571). These processes typically handle database server management and application host functions within the 1C platform, and direct external communication from them may indicate unauthorized activity or C2 traffic.
Detects the execution of Python scripts named 'exploit.py' or 'exp.py', which are common naming conventions associated with proof-of-concept or exploit code.
Page 337 of 1871




