Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects potential keylogging behavior by identifying a process masquerading as firefox.exe that is operating from an unauthorized directory while utilizing keyboard hooking (SetWindowsHookEx) or polling (GetAsyncKeyState) APIs, a technique consistent with the BabylonRAT malware.
Detects the use of PowerShell to load .NET assemblies into memory using the Assembly.Load method. This technique is often employed by adversaries to execute malicious payloads reflectively, avoiding the creation of files on disk.
Detects suspicious Python execution patterns commonly associated with web shells or remote code execution, originating from typical web server or application middleware processes (e.g., w3wp, nginx, httpd, tomcat). The detection triggers on specific patterns including base64-encoded command execution, Python evaluation of base64-encoded strings, or long alphanumeric command-line strings suggesting obfuscated code execution.
This rule detects scenarios where a specific parent process generates five or more child processes, which can be an indicator of suspicious automation, scripting activity, or potential brute-force behavior. It groups events by host and parent process image to identify potential anomalous process density.
This rule monitors for suspicious process execution patterns that suggest system tampering, security tool evasion, or data concealment. It detects activities such as clearing event logs, modifying Windows Defender preferences (exclusions/real-time monitoring), creating suspicious scheduled tasks, deleting volume shadow copies, and using PowerShell for credential or system state manipulation.
Detects when a user who has successfully authenticated to a system is subsequently added to the 'Domain Admins' group within a 15-minute window. This behavior often indicates an adversary performing privilege escalation after gaining initial access to an account.
Detects interaction with known infrastructure associated with the PREY-0058 campaign, which utilizes Adversary-in-the-Middle (AiTM) phishing lures mimicking passkey or MFA registration pages to target Microsoft 365 and other SaaS applications.
Detects interaction with known infrastructure associated with the PREY-0058 campaign, which utilizes Adversary-in-the-Middle (AiTM) phishing lures mimicking passkey or MFA registration pages to target Microsoft 365 and other SaaS applications.
Detects the Stella_Gary .NET backdoor loader used by Kimsuky/APT-C-55, identified by managed-layer reflective assembly loading strings (loader.Program.Main, AssemblyResolve callback, Stella_Gary.Program.Main)
The following analytic identifies processes running from file paths not typically associated with legitimate software. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment.
Detects instances where a process attempts to directly open or access the Active Directory domain database file (NTDS.dit). Direct access to this file is a strong indicator of credential dumping attempts, as the file contains sensitive password hashes and domain information.
Detects anomalous network traffic patterns characterized by rapid domain rotation, where multiple distinct domains resolve to a known set of IronToll C2 infrastructure IP addresses within a short timeframe (48 hours). Added an explicit 2-day lookback window — the original query had no time bound at all, so every scheduled run re-scanned the table's entire retention period and would keep re-surfacing the same historical match indefinitely instead of only genuinely recent activity.
Detects anomalous network traffic patterns characterized by rapid domain rotation, where multiple distinct domains resolve to a known set of IronToll C2 infrastructure IP addresses within a short timeframe (48 hours). Added an explicit 2-day lookback window — the original query had no time bound at all, so every scheduled run re-scanned the table's entire retention period and would keep re-surfacing the same historical match indefinitely instead of only genuinely recent activity.
Detects anomalous network traffic patterns characterized by rapid domain rotation, where multiple distinct domains resolve to a known set of IronToll C2 infrastructure IP addresses within a short timeframe (48 hours). Added an explicit 2-day lookback window — the original query had no time bound at all, so every scheduled run re-scanned the table's entire retention period and would keep re-surfacing the same historical match indefinitely instead of only genuinely recent activity.
This rule monitors DeviceNetworkEvents for outbound connections to a list of known malicious or suspicious IP addresses. This activity is indicative of potential command and control (C2) communication or unauthorized data exfiltration.
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
Detects several potentially malicious activities related to Active Directory Certificate Services (AD CS). This includes high volumes of failed requests (potential enumeration), requests for sensitive templates (privilege escalation), and potential impersonation attempts using Subject Alternative Names (SANs). These activities are associated with AD CS abuse techniques.
This rule monitors DeviceNetworkEvents for any outbound network connections made to the specific IP address 79.133.56.90. This address is identified as malicious or a known indicator of compromise (IoC) and may indicate command and control (C2) communication or unauthorized data transfer originating from a managed endpoint.
This rule detects DNS queries and network connections to a curated list of domains identified as malicious. It correlates events from DNS logs and device network logs to identify potential command-and-control (C2) or malicious infrastructure interaction.
This rule detects potential ransomware activity by correlating risky user identity events (such as impossible travel or malicious IP access) with subsequent endpoint behavior typical of ransomware, specifically the deletion of shadow copies or system backups, or mass file modification activity occurring within a short window.
This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
Page 351 of 1870



