Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potential extraction or caching of Kerberos Ticket-Granting Tickets (TGT) by correlating Kerberos authentication events (4768/4769) with unauthorized access to the Local Security Authority Subsystem Service (lsass.exe). This pattern is often indicative of credential dumping tools like Mimikatz targeting Kerberos tickets on systems potentially used for delegation attacks.
This rule detects potential Kerberoasting reconnaissance activities by monitoring for the usage of 'setspn.exe' (Event ID 4688) or LDAP queries involving 'servicePrincipalName' (Event ID 1644). Adversaries use these methods to identify service accounts in the domain to target for ticket requests.
Detects the execution of BloodHound related processes combined with a high volume of LDAP queries (Event ID 1644), which is indicative of Active Directory environment reconnaissance.
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
This rule detects potential ransomware activity by correlating three distinct indicators: deletion of Volume Shadow Copies (using native Windows utilities), mass file modifications (>100 files in 15 minutes), and the creation or modification of files typically associated with ransom notes. The rule uses an inner join to ensure these events happen within a 30-minute window of each other on the same device.
This rule detects potential ransomware activity by correlating three distinct indicators: deletion of Volume Shadow Copies (using native Windows utilities), mass file modifications (>100 files in 15 minutes), and the creation or modification of files typically associated with ransom notes. The rule uses an inner join to ensure these events happen within a 30-minute window of each other on the same device.
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
Detects the execution of rundll32.exe with a command line pointing to a WebDAV share path (DavWWWRoot). This technique is commonly used to execute remote payloads by forcing the system to access a remote resource, often as part of a malicious DLL loading chain.
Detects the GoCaracal lightweight implant performing process injection by identifying combinations of remote process memory allocation (VirtualAllocRemoteApiCall), memory writing (WriteProcessMemoryRemoteApiCall), and remote thread creation (CreateRemoteThreadApiCall) associated with specific suspicious filenames. It also monitors command-line activity for injection-related flags.
This rule monitors for active reconnaissance or scanning behavior by detecting a single source IP interacting with a high number of distinct ports/hosts within a short time frame (NetworkScan) or accessing a high number of distinct URI paths/404 errors (WebContentScan).
Detects potential web reconnaissance or scanning activity against Microsoft IIS servers. The rule identifies suspicious behavior by monitoring for high frequencies of distinct URI requests, excessive 404 Not Found status codes indicative of path brute-forcing, and the presence of known security scanning user-agents.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
Detects instances where 'TieringEngineService.exe' or 'MsMpEng.exe' (Windows Defender) create, modify, or rename executable, library, or system files within the 'C:\Windows\System32\' directory. This behavior is highly irregular as these processes should not be authoring binaries in protected system folders, and may indicate process masquerading, unauthorized persistence, or defense evasion.
Detects suspicious DLL loads or file drops performed by security product processes (avp.exe, MsMpEng.exe) from directories outside of standard, trusted vendor paths. It specifically flags unsigned or invalidly signed DLLs, which is indicative of DLL sideloading techniques used to abuse security software workflows for potential privilege escalation.
This rule detects the execution of a file named 'report.bin' and correlates it with subsequent network connections originating from the same process. This behavior is indicative of a potential C2 heartbeat or exfiltration activity involving a non-standard or obfuscated executable.
Detects the execution or presence of files, processes, or paths associated with the 'SnowKiller' malware or tool, as identified by keyword matching in process event logs.
This rule detects the installation of browser extensions that occur during an idle user session (greater than 7 minutes). This behavior is consistent with automated, remote-driven synthetic input injection, often utilized by malware (e.g., NinjaMare) to install malicious extensions without user consent while the system is unattended.
Detects the creation of PHP files within the 'wp-content/uploads/elementor/forms/' directory of a WordPress installation. This behavior is highly suspicious as it often indicates an attempt by an attacker to deploy a web shell or other malicious script following successful exploitation of the Elementor plugin, which allows for arbitrary file uploads.
Detects Evil-WinRM / WinRM-fs usage or wsmprovhost.exe-spawned PowerShell tied specifically to bird-agent backdoor artifacts (cplsupport, wtass, config.toml) or encoded/download-cradle command patterns, rather than any WinRM session, reducing noise from routine remote administration.
Page 338 of 1871

