Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
Detects remote administration activity via Windows Management Instrumentation (WMI) originating from a host that has no recorded history of performing such actions within the previous 30 days. This includes the use of wmic.exe for remote nodes, Invoke-WmiMethod, or WmiPrvSe.exe spawning common command-line interpreters or utilities.
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
Detects high-frequency, automated web scraping behavior targeting product catalog pages, indicative of content harvesting for site replication. The rule monitors IIS logs for non-browser user agents (e.g., Python, curl, Scrapy) performing rapid, multi-page requests within a short duration.
Detects high-frequency, automated web scraping behavior targeting product catalog pages, indicative of content harvesting for site replication. The rule monitors IIS logs for non-browser user agents (e.g., Python, curl, Scrapy) performing rapid, multi-page requests within a short duration.
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
Detects unauthorized devices or processes attempting to communicate with the Telegram Bot API (/sendMessage or /sendDocument) and monitors for credential-related terms within the request metadata. This often indicates the use of Telegram as a command-and-control (C2) channel for data exfiltration or credential theft.
Detects instances where the NW.js (Node-Webkit) framework binaries (nw.exe, node.exe) spawn common command-line interpreters or script-hosting utilities (e.g., cmd.exe, powershell.exe, wscript.exe) while executing associated application files like main.js or nw.pak. This behavior is indicative of potential exploitation of a browser-based application to gain shell access or execute arbitrary code on the host system.
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
This rule detects potentially malicious behavior associated with Microsoft Office applications, such as Word, initiating suspicious WebDAV network connections, dropping executable or sensitive files, or spawning known LOLBAS processes (rundll32, explorer, regsvr32) from suspicious directories like Temp or WebDAV paths. It also includes a blocklist for known malicious file hashes associated with these patterns.
This rule detects potentially malicious behavior associated with Microsoft Office applications, such as Word, initiating suspicious WebDAV network connections, dropping executable or sensitive files, or spawning known LOLBAS processes (rundll32, explorer, regsvr32) from suspicious directories like Temp or WebDAV paths. It also includes a blocklist for known malicious file hashes associated with these patterns.
This rule detects potential COM hijacking of the CLSID InprocServer32 registry keys or unauthorized loading/creation of the 'EhStoreShell.dll' file. These behaviors are common indicators of persistence mechanisms or DLL side-loading where attackers redirect legitimate system calls to malicious code.
Page 388 of 1870

