Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects presence of multiple ShieldCrash CVE-2026-69414 PoC Visual Studio project/solution build artifacts indicating exploit tooling staging
Detects high-frequency file creation, modification, or renaming activity involving files with the specific '.df_win' extension, likely indicative of mass encryption activity or automated ransomware behavior. The rule excludes known backup and security software processes to reduce noise.
Detects high-frequency TCP/445 connection attempts (a 'connect sweep') characteristic of automated SMB share enumeration, which is commonly used for lateral movement reconnaissance. The rule triggers when a threshold of 40 connection requests occurs from a single source within a 30-second window, specifically targeting SMB-related lateral movement behaviors.
Detects high-frequency TCP/445 connection attempts (a 'connect sweep') characteristic of automated SMB share enumeration, which is commonly used for lateral movement reconnaissance. The rule triggers when a threshold of 40 connection requests occurs from a single source within a 30-second window, specifically targeting SMB-related lateral movement behaviors.
Detects PowerShell scripts that utilize native PowerShell Identity modules to request Kerberos tickets.
This behavior is typically seen during a Kerberos or silver ticket attack. A successful execution will output the SPNs for the endpoint in question.
This behavior is typically seen during a Kerberos or silver ticket attack. A successful execution will output the SPNs for the endpoint in question.
Detects repeated attempts to delete Volume Shadow Copies using WMIC. This is a common technique used by ransomware and other malware to prevent system recovery and inhibit forensic investigations. The rule filters out known backup agents and service accounts and identifies patterns where multiple distinct deletions occur within a 5-minute window.
Detects repeated attempts to delete Volume Shadow Copies using WMIC. This is a common technique used by ransomware and other malware to prevent system recovery and inhibit forensic investigations. The rule filters out known backup agents and service accounts and identifies patterns where multiple distinct deletions occur within a 5-minute window.
Detects high volumes of file renaming activities involving files with the .df_win extension. This pattern is often indicative of ransomware-like behavior where mass renaming occurs as part of an encryption process, impacting multiple directories.
Detects high volumes of file renaming activities involving files with the .df_win extension. This pattern is often indicative of ransomware-like behavior where mass renaming occurs as part of an encryption process, impacting multiple directories.
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
Detects indicators of the ProRAM malware dropper, specifically identifying the download of 'sideload.exe' from an external IP or the presence of file artifacts related to its staging process in %TEMP% and %LOCALAPPDATA% directories.
Detects the loading of the ProRAM implant DLL (somkernl.dll) when initiated by known sideloading carriers such as 360speedld.exe or SoftupNotify.exe, which are signed utilities frequently abused for this purpose.
Detects the presence of known artifacts associated with the GreenSection proof-of-concept exploit, including the source code file 'GreenSection.cpp', a specific driver crash dump 'nvoglv64.dmp', and a associated unique GUID. These files are indicators that an actor has staged exploit materials on the system.
Detects the addition of a 'msDS-KeyCredentialLink' attribute to an Active Directory object (Event 5136), which is indicative of the Shadow Credentials attack vector, followed by a successful PKINIT authentication (Event 4768) for that account. This combination suggests that an adversary has successfully established persistent access using a forged or unauthorized device credential and is now utilizing it for authentication.
Detects the starting of the RemoteRegistry service via command-line utilities such as 'sc.exe' or 'net.exe'. This service is often started by adversaries to facilitate remote access to the Windows Registry for reconnaissance or enumeration of logon sessions.
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to execute processes, particularly when a remote node target is specified or when using common WMI process creation arguments. This pattern is commonly used by adversaries for lateral movement and remote code execution while attempting to blend into administrative activity. Legitimate management tools have been excluded from the scope to reduce noise.
Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
Detects anomalous system reconnaissance activity performed using WMIC or PowerShell Get-WmiObject commands. The rule tracks distinct command-line executions per device and flags hosts where three or more unique reconnaissance commands are executed within a short timeframe, which is indicative of an adversary enumerating system configuration, hotfixes, or hardware details.
Detects anomalous system reconnaissance activity performed using WMIC or PowerShell Get-WmiObject commands. The rule tracks distinct command-line executions per device and flags hosts where three or more unique reconnaissance commands are executed within a short timeframe, which is indicative of an adversary enumerating system configuration, hotfixes, or hardware details.
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
Page 387 of 1870





