Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors for potential persistence and malicious activity by aggregating three distinct detection signals: COM hijacking attempts via the InprocServer32 registry key, the creation of scheduled tasks using specific suspicious naming conventions, and the identification of named mutexes indicative of specific malware presence.
Detects the legitimate wmpnetwk.exe process, commonly used as a target for ShadowPad process injection, initiating outbound network connections while simultaneously accessing Firefox browser profile data. This behavior is indicative of credential theft and command-and-control communication typical of post-compromise activity.
Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
Detects text/report artifacts (markdown, JSON, plain text) produced by an autonomous AI-driven vulnerability research pipeline that decompiles binaries, traces cross-references, hypothesizes memory-safety flaws, and generates/debugs proof-of-concept exploits
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
This rule detects potentially unauthorized process executions (such as shells, network utilities, or enumeration tools) originating from TeamCity server processes (java.exe, javaw.exe). It filters out known TeamCity build agent or maintenance activities to highlight deviations from standard server behavior.
Identifies devices running versions of Chromium-based browsers (such as Chrome) vulnerable to CVE-2026-85046, a V8 type confusion vulnerability that allows remote code execution within the browser sandbox.
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
Page 378 of 1870


