Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects OAuth2 JWT bearer-grant token requests to Google's OAuth endpoint using the attacker-controlled service-account identity and Sheets API scope observed in the fake GlobalProtect campaign
Detects network requests to Google Sheets API containing specific markers (-tk- or val-) in the request body, indicative of potential command and control (C2) communication patterns often associated with malware payloads using Google Sheets for data exfiltration or command retrieval.
Detects Mimikatz binary or in-memory module used for credential harvesting following PaperCut RCE exploitation
Detects Mimikatz binary or in-memory module used for credential harvesting following PaperCut RCE exploitation
Detects the execution of BloodHound/SharpHound reconnaissance tools and the presence of their generated output files (ZIP or JSON format) on a host. This rule monitors both the process creation events associated with the tool's execution and file creation events indicative of data staging or collection output.
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to execute processes, particularly when a remote node target is specified or when using common WMI process creation arguments. This pattern is commonly used by adversaries for lateral movement and remote code execution while attempting to blend into administrative activity. Legitimate management tools have been excluded from the scope to reduce noise.
Detects anomalous system reconnaissance activity performed using WMIC or PowerShell Get-WmiObject commands. The rule tracks distinct command-line executions per device and flags hosts where three or more unique reconnaissance commands are executed within a short timeframe, which is indicative of an adversary enumerating system configuration, hotfixes, or hardware details.
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
Page 346 of 1870

