Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects the deletion of Volume Shadow Copies and disabling of Windows boot recovery options using native administrative utilities such as vssadmin, wmic, powershell, wbadmin, and bcdedit. This behavior is frequently associated with pre-encryption activities in ransomware attacks to prevent system restoration.
Detects potential reflective DLL injection or process hollowing attempts by monitoring for high-privilege cross-process access (ProcessAccess EventID 10) or remote thread creation (CreateRemoteThread EventID 8). These methods are frequently used by attackers to execute malicious code within the memory space of a legitimate target process, thereby evading traditional signature-based detection.
Detects the suspicious execution of common Windows system binaries (LOLBAS) often used for proxying malicious code execution or deobfuscating payloads. This includes regsvr32.exe for remote scriptlet execution, mshta.exe for remote HTA execution, rundll32.exe for JavaScript or DLL function execution, and certutil.exe for decoding or retrieving remote files.
Detects potential Pass-the-Hash (PtH) activity where a single user account performs NTLM Type 3 (network) authentications to three or more unique destination hosts within a 10-minute window, excluding service account activity (trailing $). This pattern is consistent with an adversary moving laterally across a network using harvested NTLM hashes.
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in-memory by monitoring command lines of common script-hosting processes (e.g., PowerShell, WScript, Rundll32) for strings indicative of AmsiScanBuffer patching, reflection, or manual configuration of AMSI initialization states.
Detects the use of the built-in Windows utility rundll32.exe to execute comsvcs.dll with the MiniDump command to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. This is a common technique used by attackers to harvest credentials from memory.
Detects the use of native Windows utilities (vssadmin, wbadmin, bcdedit, wmic) to delete shadow copies, backup catalogs, or modify boot configuration data to disable recovery. This behavior is commonly associated with ransomware and data destruction attacks intended to prevent system restoration.
This rule detects unauthorized directory replication requests (DRSUAPI) using Active Directory Event ID 4662. It specifically monitors for access requests to sensitive directory replication object GUIDs (Get-Changes / Get-Changes-All) where the requesting user account is not a domain controller computer account. This behavior is a common indicator of DCSync credential dumping attacks performed by tools like Mimikatz or Impacket.
Detects the 'ClickFix' technique where a user copies a malicious payload and pastes it into the Windows Run dialog (Win+R). The rule monitors for the creation of registry values under the RunMRU key followed closely by the execution of powershell.exe or cmd.exe initiated directly by explorer.exe, indicating an bypass of standard browser execution chains.
This rule detects persistence establishment via Scheduled Task creation shortly (within 15 minutes) after a suspicious PowerShell process execution. The PowerShell execution matches the 'ClickFix' pattern, characterized by hidden/bypass window styles and the invocation of remote download or execution cmdlets (e.g., IEX, IRM).
This rule detects potentially malicious in-memory module loading, such as Beacon Object File (BOF) execution, on hosts already identified as exhibiting suspicious behavior related to MLTBackdoor or sideloading activity. It monitors for memory allocation or protection changes (AllocateVirtualMemory, VirtualProtect, CreateRemoteThread) that result in executable memory (RWX or execute-only) without a corresponding file on disk, which is a common indicator of fileless code injection.
This rule detects potential Browser-in-the-Browser (BitB) phishing attacks by identifying suspicious browser pop-up behavior (using window.open flags, hidden address/toolbars) on non-identity-provider domains, followed shortly by credential submission patterns on the same device. This pattern mimics legitimate OAuth or SSO windows to harvest user credentials.
Detects anomalous access to the SharePoint WebPartPages.asmx SOAP endpoint, specifically using the GetWebPartPageConnectionInfo method. This query identifies patterns consistent with the exploitation of CVE-2026-65660, where adversaries attempt to smuggle WebPart template markup (e.g., <%@ Register, XamlServices) after legitimate preview methods have been disabled.
This rule detects potentially malicious POST requests to SharePoint endpoints (such as AddGallery.aspx) that include indicators of WebPartMarkup or ToolPane payloads. This activity attempts to bypass the SPUtility.EnsureAuthentication() check that is typically enforced on the ToolPane.aspx page, potentially allowing unauthorized code execution or configuration manipulation.
Detects the execution of binaries that masquerade as legitimate Adobe-signed applications by running from non-standard locations, while simultaneously performing DLL side-loading by loading a malicious 'msvcp140.dll' from the same directory as the executable.
This rule monitors for known suspicious RPC interface and function calls indicative of post-exploitation activities. It specifically targets RPC patterns used for lateral movement (e.g., PsExec, wmiexec, dcomexec), authentication coercion (e.g., PetitPotam, PrinterBug), and credential theft (e.g., DCSync, SAMR enumeration) by filtering on specific interface UUIDs and operation numbers.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Page 36 of 1866



