Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
This rule detects potentially malicious usage of the Windows RegSvcs.exe binary, often used as a proxy for executing code. It monitors for two specific patterns: RegSvcs.exe being executed from user-writable directories (e.g., C:\Users\, C:\ProgramData\), or RegSvcs.exe spawning suspicious child processes (e.g., PowerShell, cmd, WScript, mshta), which is indicative of a living-off-the-land (LotL) attack technique to bypass application control or execute payloads.
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
Detects an exploitation attempt against the Vite Development Server (CVE-2026-39364) where an attacker uses specific query parameters to bypass file access restrictions and disclose sensitive files. The rule triggers on GET requests containing suspicious import-related query parameters and checks the resulting response to ensure a successful 200/206 status code and non-HTML content type.
Detects an exploitation attempt against the Vite Development Server (CVE-2026-39364) where an attacker uses specific query parameters to bypass file access restrictions and disclose sensitive files. The rule triggers on GET requests containing suspicious import-related query parameters and checks the resulting response to ensure a successful 200/206 status code and non-HTML content type.
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
Detects the execution of known Windows accessibility binaries (e.g., sethc.exe, utilman.exe) where the internal metadata or original filename indicates that the process is actually cmd.exe. This is a common technique used by adversaries to gain unauthenticated command-line access with SYSTEM privileges via accessibility features, typically during the login screen process.
BigBear 2.0 IOC HUNT (Cortex XDR)
Cortex XDR
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
BigBear 2.0 IOC HUNT (Gravwell)
Gravwell
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
BigBear 2.0 IOC HUNT (Gravwell)
Gravwell
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
Detects network connections to known command and control (C2) infrastructure, including hardcoded malicious domains, specific C2 IP addresses, and suspicious GitHub access patterns by processes other than standard web browsers, which may indicate malicious ingress tool transfer or C2 communication.
Detects instances of the Windows utility RegSvcs.exe being executed from suspicious, user-writable directories (such as Temp or Public folders) or instances where RegSvcs.exe is used to spawn common command-line or scripting tools, which is a common indicator of living-off-the-land binary (LOLBin) abuse.
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
Detects instances where VLC media player is launched from common temporary or untrusted directories (e.g., Downloads, Temp) with media files and subsequently crashes within a short window (2 minutes), as indicated by a corresponding werfault.exe error report. This behavior may indicate an attempt to exploit vulnerabilities within the VLC application by using a maliciously crafted file.
This rule detects potentially malicious behavior by correlating intensive usage of graphics-related API calls (like BitBlt, GetDC, etc.) which are indicative of screen capture, with the execution of specific command identifiers typically associated with C2 (Command and Control) traffic. The combination suggests an adversary is capturing screen data and potentially staging or exfiltrating it via a C2 channel.
This rule monitors for network connections to known command-and-control (C2) IP addresses and the execution or presence of files matching known hashes associated with the 'PhantomC2' threat group or malware family. It correlates data from DeviceNetworkEvents, DeviceFileEvents, and DeviceProcessEvents to identify potential compromise.
Detects ClickFix-style social engineering attacks where users are prompted to copy and execute malicious commands in a shell environment. The rule triggers on process execution of terminal or shell binaries (zsh, sh, cmd.exe, powershell.exe) containing indicators of obfuscated execution or remote code downloading, such as piped shell commands (curl | sh/zsh) or PowerShell encoded command execution.
Detects high-frequency screen capture activity by monitoring process module loads related to BitBlt, GDI32.dll, and explicit screen capture descriptions. This rule identifies sustained screen scraping behavior (50+ events within a 5-minute window) indicative of the SparroWocky malware surveillance module's screen monitoring functionality.
This rule monitors Portable Executable (PE) files to identify those signed with certificates associated with Discord Inc. or Lenovo. Adversaries frequently abuse stolen or fraudulently obtained code-signing certificates from legitimate, reputable companies to bypass security controls like Windows SmartScreen, gain persistence, or increase the likelihood of successful malware execution.
Page 353 of 1870



