Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
Detects potential remote service session hijacking by monitoring for RDP session ID reuse by a different user or unauthorized SSH session reattachment (e.g., tmux/screen hijacking). It correlates logon events with process execution to identify instances where an existing session is accessed by an account other than the original owner, while excluding legitimate service/support account activity.
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
This rule detects potentially malicious usage of the Windows RegSvcs.exe binary, often used as a proxy for executing code. It monitors for two specific patterns: RegSvcs.exe being executed from user-writable directories (e.g., C:\Users\, C:\ProgramData\), or RegSvcs.exe spawning suspicious child processes (e.g., PowerShell, cmd, WScript, mshta), which is indicative of a living-off-the-land (LotL) attack technique to bypass application control or execute payloads.
Page 352 of 1870

