Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects post-exploitation persistence artifacts on Windows endpoints consistent with abuse of CVE-2026-18577.
Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.
This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
This rule detects the creation of Windows services with specific, potentially suspicious names (wscl-13, msvcsrvc) configured to start automatically on system startup. The detection logic monitors command-line activity from sc.exe or services.exe to identify these specific service registrations.
Detects the use of PowerShell to modify Microsoft Defender Antivirus configurations, specifically adding file exclusions or disabling protection features like Real-time or IOAV monitoring. These actions are common indicators of an adversary attempting to disable security controls to evade detection.
Detects the modification or creation of scheduled tasks using OOBETaskScheduler or referencing Windows Servicing paths, combined with network connections to known malicious domains identified in threat intelligence.
This KQL inventories activity associated with a specified root domain and its subdomains across DeviceNetworkEvents, EmailUrlInfo, CloudAppEvents.
This rule detects potential COM hijacking of the CLSID InprocServer32 registry keys or unauthorized loading/creation of the 'EhStoreShell.dll' file. These behaviors are common indicators of persistence mechanisms or DLL side-loading where attackers redirect legitimate system calls to malicious code.
Detects the presence of known malicious Outlook VBA project files (VbaProject.OTM), modifications to Outlook macro-security registry keys to enable macro execution, and subsequent network activity initiated by Outlook on devices that have exhibited these suspicious behaviors.
Detects the presence of known malicious Outlook VBA project files (VbaProject.OTM), modifications to Outlook macro-security registry keys to enable macro execution, and subsequent network activity initiated by Outlook on devices that have exhibited these suspicious behaviors.
This rule detects potentially malicious behavior associated with Microsoft Office applications, such as Word, initiating suspicious WebDAV network connections, dropping executable or sensitive files, or spawning known LOLBAS processes (rundll32, explorer, regsvr32) from suspicious directories like Temp or WebDAV paths. It also includes a blocklist for known malicious file hashes associated with these patterns.
Detects the download of ZIP files with filenames matching known phishing patterns associated with NFe (Nota Fiscal Eletrônica) campaigns, correlated with access to specific malicious or suspicious download URLs within a 15-minute window.
Detects the execution of known Windows update-related binaries (UpdateAssistant.exe or AppUpdateHelper.exe) from non-standard, suspicious locations within AppData directories. This behavior is indicative of masquerading, where an adversary attempts to blend in by using a legitimate process name from an unexpected path.
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
Detects a specific pattern of PowerShell execution involving the download of files from a remote endpoint using parameters associated with Brazilian tax documents (NotaFiscal) to the Desktop directory, followed by immediate execution. The rule looks for a combination of hidden window style, Invoke-WebRequest, specific URL parameters (dl.php, NFe identifiers), and subsequent Start-Process calls, which is indicative of malware dropper activity.
Detects the execution of Python scripts explicitly named 'socks5.py'. This is a common pattern used by adversaries to establish proxying capabilities for command and control or to tunnel traffic through a compromised host.
This rule detects attempts to disable, terminate, or misconfigure security software, including antivirus, EDR, and endpoint protection solutions, by monitoring the execution of system administration binaries (such as taskkill, net, sc, wmic, powershell) with command-line arguments indicating service or process stopping, deletion, or configuration changes related to security-specific product names.
This rule detects potential tampering with the Huorong security product by monitoring for specific process names (HipsTray.exe, HipsMain.exe, HipsDaemon.exe, wsctrlsvc.exe, TrafficProt.exe) interacting with suspicious API calls or command lines indicative of token privilege manipulation, service blinding, or security product disabling/downgrade.
Detects network requests to Google Sheets API containing specific markers (-tk- or val-) in the request body, indicative of potential command and control (C2) communication patterns often associated with malware payloads using Google Sheets for data exfiltration or command retrieval.
Page 369 of 1870




