Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects network activity associated with Rust-based stealer malware, specifically focusing on connections to a known C2 IP address (31.76.7.137) or HTTP requests directed at static-asset paths (e.g., analytics.gif, pixel.png, content.js) when the destination is an IPv4-literal address. This behavior is indicative of C2 beacons or data exfiltration disguised as legitimate web traffic.
Detects network activity associated with Rust-based stealer malware, specifically focusing on connections to a known C2 IP address (31.76.7.137) or HTTP requests directed at static-asset paths (e.g., analytics.gif, pixel.png, content.js) when the destination is an IPv4-literal address. This behavior is indicative of C2 beacons or data exfiltration disguised as legitimate web traffic.
This rule detects successful outbound network connections to the domain 'gapidriver.com' targeting the URI path '/api/get.php'. This pattern is associated with command and control (C2) activity. Due to the lack of specific HTTP header validation in this telemetry source, the signal may require additional validation, such as analyzing the initiating process lineage.
This rule detects successful outbound network connections to the domain 'gapidriver.com' targeting the URI path '/api/get.php'. This pattern is associated with command and control (C2) activity. Due to the lack of specific HTTP header validation in this telemetry source, the signal may require additional validation, such as analyzing the initiating process lineage.
This rule detects successful outbound network connections to the domain 'gapidriver.com' targeting the URI path '/api/get.php'. This pattern is associated with command and control (C2) activity. Due to the lack of specific HTTP header validation in this telemetry source, the signal may require additional validation, such as analyzing the initiating process lineage.
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
Detects post-exploitation persistence artifacts on Windows endpoints consistent with abuse of CVE-2026-18577.
Page 368 of 1870
