Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a single process accessing multiple distinct sensitive files related to cryptocurrency wallets, SSH keys, or seed phrases within a short duration. This pattern of bulk file access is highly indicative of automated credential harvesting modules like those found in the CRPx0 malware family.
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
Detects unauthorized modifications to critical authentication-related configuration files and registry keys. Specifically monitors changes to LSA security packages and notification packages on Windows systems, as well as PAM configuration file modifications on Linux systems, when performed by unsigned or untrusted processes outside of known installer activity.
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
This rule detects unauthorized attempts to modify CrowdStrike Falcon sensor exclusion registry keys or commands involving DLL loading techniques that may indicate evasion preparation, specifically referencing potential FalconFlank-related activities. It filters out legitimate management activity from known service accounts, SCCM, and the CrowdStrike Falcon agent itself.
Detects anomalous network traffic patterns characterized by rapid domain rotation, where multiple distinct domains resolve to a known set of IronToll C2 infrastructure IP addresses within a short timeframe (48 hours). Added an explicit 2-day lookback window — the original query had no time bound at all, so every scheduled run re-scanned the table's entire retention period and would keep re-surfacing the same historical match indefinitely instead of only genuinely recent activity.
This rule monitors network traffic from internal devices and security logs for communication with a curated list of known malicious or suspicious scanner IP addresses, indicating potential reconnaissance or probing activity by external actors.
This rule monitors network traffic from internal devices and security logs for communication with a curated list of known malicious or suspicious scanner IP addresses, indicating potential reconnaissance or probing activity by external actors.
Detects a potential Kerberoasting attempt by identifying a single user or IP requesting multiple RC4-encrypted Ticket Granting Service (TGS) tickets for distinct service accounts within a short timeframe. Kerberoasting involves requesting TGS tickets for service accounts, which are then used for offline brute-force cracking of the service account's password hash.
Detects anomalous remote interactive or network logons where the specific account and remote host/IP combination has not been observed in the previous 14 days. The rule correlates these new login events with subsequent process execution on the destination host within a short window (5 minutes) to identify potential lateral movement where an adversary uses valid credentials to log in and immediately execute commands.
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
This rule monitors DeviceNetworkEvents for outbound connections to a list of known malicious or suspicious IP addresses. This activity is indicative of potential command and control (C2) communication or unauthorized data exfiltration.
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
This rule monitors DeviceNetworkEvents for outbound connections to a list of known malicious or suspicious IP addresses. This activity is indicative of potential command and control (C2) communication or unauthorized data exfiltration.
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
Page 380 of 1870



