Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects suspicious file operations (creation, modification, or renaming) initiated by MsMpEng.exe (Microsoft Defender Antivirus) involving specific indicators related to ELAM (Early Launch Anti-Malware) or 'ShieldCrash' components. These indicators often suggest tampering attempts or the presence of tools designed to interfere with Defender's security operations by targeting its configuration, staging, or protected storage locations.
This rule detects suspicious file operations (creation, modification, or renaming) initiated by MsMpEng.exe (Microsoft Defender Antivirus) involving specific indicators related to ELAM (Early Launch Anti-Malware) or 'ShieldCrash' components. These indicators often suggest tampering attempts or the presence of tools designed to interfere with Defender's security operations by targeting its configuration, staging, or protected storage locations.
Detects the Warden.dll companion DLL shipped as part of the ShieldCrash (CVE-2026-69414) exploit chain, tightened to require an unsigned/unknown publisher or a suspicious install path alongside the generic filename
Detects unexpected crashes or restarts of the Windows Defender service (MsMpEng.exe) occurring in temporal proximity to activities associated with the ShieldCrash PoC or tampering within the Windows Defender object manager namespace. This rule aims to identify potential exploitation attempts targeting Windows Defender, specifically correlating security service instability with known malicious indicators.
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
This rule detects potentially malicious activity associated with removable media (USB drives) by identifying two distinct patterns: first, the creation of an 'autorun.inf' file on a removable drive followed by the execution of a script or executable from that same drive shortly after. Second, it identifies executables appearing on removable media that are launched across multiple distinct hosts within a one-hour window, which may indicate worm-like spreading or mass-malware distribution via portable storage.
Detects instances where an Azure AD Connect or MSOL synchronization account performs directory replication actions (DS-Replication-Get-Changes) from a host or at a time inconsistent with its 14-day established baseline. The rule further correlates these anomalies with Azure Audit logs or AzureActivity entries associated with the identity to identify potential cloud-originated abuse or credential compromise.
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
AS-REP Roasting Potential Enumeration
Cortex XDR
Detects Kerberos AS-REQ events (Event ID 4768) where accounts with Kerberos pre-authentication disabled successfully request an AS-REP ticket. Attackers exploit these accounts by requesting encrypted AS-REP blobs to perform offline password cracking. The rule flags potential enumeration when multiple unique accounts are targeted from the same source within a short timeframe.
Detects the loading of reflective (memory-only) DLLs within the chrome.exe process address space. This activity is indicative of memory-based exploit chains, such as those that corrupt WebAssembly module metadata to facilitate arbitrary code execution following a sandbox escape.
Detects token duplication/impersonation targeting winlogon.exe to obtain SYSTEM privileges (SeDebugPrivilege abuse, DuplicateToken, SetTokenInformation to Untrusted integrity)
Detects known malicious file hashes for GRAYRABBIT delivery chain components: trojanized 7zp.dll loader, encrypted PE loader shellcode, and GRAYRABBIT backdoor core.dll, gated on PE structural validity and filesize
This rule detects the presence or execution of a file named 'GlobalProtect.exe' within the Palo Alto GlobalProtect directory. It focuses on identifying potentially masqueraded or unauthorized binaries by monitoring file events and associated process execution. This pattern is commonly used by attackers to disguise malicious files as legitimate security software to evade detection.
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
Detects suspicious activities originating from CrowdStrike Falcon remediation processes (e.g., CSFalconService.exe, CSFalconContainer.exe). The rule identifies two distinct patterns: either a file operation (delete, modify, rename, quarantine, or restore) followed within 2 minutes by the loading of an unsigned or non-standard DLL, or the spawning of an elevated SYSTEM process from a non-SYSTEM parent process. This behavior is indicative of potential LPE (Local Privilege Escalation) abuse via the Falcon remediation engine, often referred to as FalconFlank-style exploitation.
Detects a sequence of events where a user visits a Cloudflare Pages URL (*.pages.dev) and shortly after, a suspicious command (mshta, powershell, or curl) is executed. This pattern is consistent with the UNC5142 threat actor's TTP of using social engineering lures hosted on Cloudflare Pages to trick users into running malicious commands.
Page 364 of 1870



