Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
Detects remote administration activity via Windows Management Instrumentation (WMI) originating from a host that has no recorded history of performing such actions within the previous 30 days. This includes the use of wmic.exe for remote nodes, Invoke-WmiMethod, or WmiPrvSe.exe spawning common command-line interpreters or utilities.
Detects modifications to Windows Registry keys intended to disable System Restore, User Account Control (UAC), or automatic Windows Updates, which is indicative of an attacker attempting to impair system defenses or inhibit recovery capabilities.
Detects the creation of ransom notes by the OpnKey ransomware family, which specifically uses the filename #Restore-My-Files.txt. This file is a characteristic indicator of the ransomware's post-encryption activity.
Detects forged Citibank payment confirmation/account statement PDFs used in Phantom Deal BPC fraud to falsely demonstrate wire transfer progress; requires combination of bank branding with fraud-specific SWIFT/routing/CTA artifacts
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
Detects instances where node, npm, or bun package installation processes modify the Claude AI settings.json file. This could indicate potential supply chain compromise or unauthorized configuration changes to the Claude application environment via malicious packages or scripts.
Detects instances where the GlobalProtect VPN client executable spawns a Windows command shell (cmd.exe). This behavior is highly suspicious as a legitimate VPN client typically does not launch interactive shells, and this pattern has been associated with the execution of malicious payloads such as fake MSI installers.
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
Detects the creation of files named 'strEncodedData.txt' on the local file system. This naming convention is associated with the DarkTortilla RAT, which uses this specific file to stage encoded data prior to exfiltration or further processing.
Detects processes using Python shutil.copyfile to harvest sensitive browser data files from Chromium-based profiles.
Detects suspicious Kerberos ticket requests via command line using System.IdentityModel.Tokens.KerberosRequestorSecurityToken class.
Threat actors may use command line interfaces to request Kerberos tickets for service accounts in order to
perform offline password cracking attacks commonly known as Kerberoasting or other Kerberos ticket abuse
techniques like silver ticket attacks.
Threat actors may use command line interfaces to request Kerberos tickets for service accounts in order to
perform offline password cracking attacks commonly known as Kerberoasting or other Kerberos ticket abuse
techniques like silver ticket attacks.
Detects the execution of known offensive security tools often used for lateral movement, credential dumping, and remote code execution, such as Impacket modules and the 'Invoke-TheHash' PowerShell suite, via common command-line interpreters.
This rule monitors for process creation or file interaction events associated with a specific SHA256 file hash identified as malicious. It uses Microsoft Defender for Endpoint (MDE) logs to correlate both process execution and file activity related to this indicator of compromise.
This rule detects network connections and HTTP requests to known malicious URLs, including file downloads associated with C2 infrastructure and malware distribution campaigns. It monitors both direct device network events and HTTP requests logged through security product events to identify potential secondary-stage payload delivery.
This rule monitors for outbound network connections to domains and IP addresses associated with known phishing, loader, and C2 infrastructure, including specific ClickFix patterns.
Page 361 of 1870






