Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the GoCaracal lightweight implant performing process injection by identifying combinations of remote process memory allocation (VirtualAllocRemoteApiCall), memory writing (WriteProcessMemoryRemoteApiCall), and remote thread creation (CreateRemoteThreadApiCall) associated with specific suspicious filenames. It also monitors command-line activity for injection-related flags.
Detects a pattern of multiple failed authentication attempts (brute force) from an external IP address followed by a successful authentication event on remote access services such as RDP, VPN, or NTLM. The rule filters for non-private IP addresses and flags successes occurring outside of standard business hours.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
Detects instances where base64-encoded PHP code, obfuscated behind a 'data:image/gif;base64' MIME type prefix, is written to the disk as a .php file or initiated by web server processes. This pattern is commonly used in file upload bypass attacks to execute arbitrary code.
Detects modifications to the 'metrics_interval' registry value within the 'Software\SynapseAgent' key. This activity suggests configuration changes to the SynapseAgent, which could indicate tampering with agent telemetry or polling frequency.
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
Detects the execution of processes named 'ProManager.exe' or 'ProManagerServicedc894.exe', which may be indicative of unauthorized software or potentially malicious activity.
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
Detects anomalous registry enumeration or modification activities targeting software uninstallation registry keys (Run/Uninstall). By monitoring for multiple subkey accesses by processes not associated with standard software management tools (like MsiExec or explorer), this rule identifies potential reconnaissance or software discovery patterns indicative of malicious activity.
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
Detects Node.js or Electron processes executing from suspicious paths (e.g., Temp, Roaming) while interacting with web browser credential files or executing commands consistent with automated credential dumping tools.
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
Detects instances where common web browsers (msedge, chrome, firefox, iexplore, brave, opera) are initiated with a command line containing a specific suspicious domain 'llove-kitchens.com', indicating potential interaction with a malicious web resource.
Detects interaction with known infrastructure associated with the PREY-0058 campaign, which utilizes Adversary-in-the-Middle (AiTM) phishing lures mimicking passkey or MFA registration pages to target Microsoft 365 and other SaaS applications.
Detects actions taken by Windows Defender malware detection engines
Page 390 of 1870


