Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
Detects forged NDA documents used in Phantom Deal fake acquisition fraud, requiring corroborating secrecy-clause language and M&A-fraud-specific wire-transfer/payment phrasing alongside impersonated advisory brands
Detects remote registry operations performed through the Winreg RPC interface. This behavior is commonly associated with adversary tools like secretsdump used to extract sensitive Windows registry hives such as SAM, SECURITY, and SYSTEM. Monitoring remote registry access is crucial for identifying unauthorized data collection and credential access attempts.
Detects the installation or execution of common remote monitoring and management (RMM) tools, including AnyDesk, TeamViewer, ScreenConnect, and Quick Assist. These tools are frequently abused by adversaries for persistence and command-and-control post-compromise.
Detects network connection attempts to specific external domains associated with suspicious JavaScript payloads. The rule filters for specific file paths (e.g., mpackage.js, bsc-loader.js) linked to known malicious or suspicious URL patterns on cdn.claritydelivr.com, rcrsinnovations.com, konverto.in, and cdn.api-middle-connect.com, which may indicate C2 beaconing or malware infection.
Detects post-exploitation persistence artifacts on Windows endpoints managed by N-able N-central consistent with abuse of CVE-2026-18577, including a new Windows service named Cloudflared, registry Services key creation for Cloudflared, a file named svchost.exe written under a user's Documents folder, or process execution of cloudflared.exe or a Documents-located svchost.exe.
Detects unauthorized processes accessing sensitive web browser files (login data, cookies, local state) from suspicious or non-standard paths. This is a common behavioral pattern for infostealers attempting to exfiltrate user credentials and browser session tokens.
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
Detects the ShieldCrash CVE-2026-69414 exploit PoC binary/PDB via multiple corroborating distinguishing strings and file size
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
Detects presence of multiple ShieldCrash CVE-2026-69414 PoC Visual Studio project/solution build artifacts indicating exploit tooling staging
Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.
Detects Run key persistence pointing to the known VBScript staging directory (C:\Users\Public\Libraries\Default\Lib\Lib1) used by the worm-like ScreenConnect campaign (Aug 2026), matching known script filenames (WindowsServiceHost.vbs, 1.vbs-4.vbs) invoked via wscript.exe/cscript.exe.
This rule detects potential COM hijacking of the CLSID InprocServer32 registry keys or unauthorized loading/creation of the 'EhStoreShell.dll' file. These behaviors are common indicators of persistence mechanisms or DLL side-loading where attackers redirect legitimate system calls to malicious code.
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
This rule detects modifications to the security descriptors (ACLs) of sensitive Active Directory objects, specifically targeting additions of powerful rights like GenericAll, GenericWrite, WriteDacl, or ForceChangePassword. Monitoring these changes on privileged objects such as Domain Admins, Enterprise Admins, and Domain Controllers is critical for detecting potential privilege escalation or persistence efforts.
Page 347 of 1870



