Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential reflective code injection or in-memory loading (fileless) where a DLL or PE image is loaded by mshta.exe or powershell.exe, but the module load event lacks a valid file path on disk (or indicates a device path). This behavior is often associated with the execution of malicious payloads such as the Amatera loader, where payloads are executed directly in memory to evade file-based security detections.
Detects instances where common web browsers (msedge, chrome, firefox, iexplore, brave, opera) are initiated with a command line containing a specific suspicious domain 'llove-kitchens.com', indicating potential interaction with a malicious web resource.
Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
Detects several potentially malicious activities related to Active Directory Certificate Services (AD CS). This includes high volumes of failed requests (potential enumeration), requests for sensitive templates (privilege escalation), and potential impersonation attempts using Subject Alternative Names (SANs). These activities are associated with AD CS abuse techniques.
Detects successful Kerberos PKINIT authentication (Event 4768, PreAuthType 16) issued by on-premises certificate authorities. This activity is a potential indicator of Shadow Credentials or Active Directory Certificate Services (AD CS) abuse where attackers use forged or stolen certificates to authenticate as domain users or machines.
Detects network connection attempts to specific external domains associated with suspicious JavaScript payloads. The rule filters for specific file paths (e.g., mpackage.js, bsc-loader.js) linked to known malicious or suspicious URL patterns on cdn.claritydelivr.com, rcrsinnovations.com, konverto.in, and cdn.api-middle-connect.com, which may indicate C2 beaconing or malware infection.
This rule monitors for network connections, firewall traffic, and Entra ID authentication events involving known malicious IP addresses (the 'Wall of Shame'). The rule specifically flags interactions occurring over common VPN ports, suggesting potential unauthorized access or persistence attempts via VPN services.
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
This rule detects potential cryptocurrency mining activity where known miner executables (specifically XMRig) or malicious scripts/processes are masquerading as or being spawned by 'LockAppHost.exe' or 'LockAppHost14a02b.exe'. It also monitors for subsequent attempts by these processes to terminate security-related tasks or establish persistence via registry run keys.
Identifies devices running versions of Chromium-based browsers (such as Chrome) vulnerable to CVE-2026-85046, a V8 type confusion vulnerability that allows remote code execution within the browser sandbox.
Identifies instances of Google Chrome running on endpoints with version numbers below the threshold patched for CVE-2026-85046. This detection focuses on specific build numbers (e.g., 152.0.7977.82 for Windows/Linux) to identify potentially vulnerable browser installations in the environment.
Identifies devices running versions of Chromium-based browsers (such as Chrome) vulnerable to CVE-2026-85046, a V8 type confusion vulnerability that allows remote code execution within the browser sandbox.
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
Detects network connection attempts to specific external domains associated with suspicious JavaScript payloads. The rule filters for specific file paths (e.g., mpackage.js, bsc-loader.js) linked to known malicious or suspicious URL patterns on cdn.claritydelivr.com, rcrsinnovations.com, konverto.in, and cdn.api-middle-connect.com, which may indicate C2 beaconing or malware infection.
Detects suspicious activity associated with the exploitation of a vulnerability in N-central (CVE-2026-86218). The rule monitors for unauthorized child process spawning by N-central components, creation of files in the application directory consistent with web shells, outbound network connections indicative of command and control, and the creation of new local or service accounts for persistence.
Detects network activity from infrastructure provisioner tools (Terraform, Coder) or shell processes attempting to connect to suspicious domains (e.g., coder-infra.com) that resemble legitimate infrastructure domains. This activity is indicative of credential theft, specifically targeting OIDC tokens, SSH keys, or authentication tokens during automated provisioning processes.
This rule detects command line patterns associated with common Impacket tools (wmiexec, psexec, smbexec) executed via Windows processes (cmd.exe, powershell.exe) or via network connections to ports 445 and 135 initiated by Python processes. These tools are frequently used by adversaries for lateral movement, remote service execution, and command execution on compromised systems.
Detects Java-based Metasploit/Meterpreter payload files (.class/.jar) dropped post-exploitation, as observed following PaperCut RCE exploitation chain
Detects Java-based Metasploit/Meterpreter payload files (.class/.jar) dropped post-exploitation, as observed following PaperCut RCE exploitation chain
Page 391 of 1870


