Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
This rule detects modifications to Group Policy Objects (GPO) or Microsoft Entra (formerly Azure AD) policies that weaken established security controls. For GPO, it monitors Event ID 5136 for changes to security-relevant attributes (e.g., disabling firewall or real-time monitoring) in Active Directory. For Entra, it monitors audit logs for administrative operations that reduce security posture, such as disabling MFA, lowering authentication trust, or deleting Conditional Access policies. It includes filters to exclude legitimate, documented change management activities.
Detects msiexec.exe executing from the Temp directory with suspicious command-line arguments (such as hidden windows) and spawning child processes like cmd.exe, tasklist.exe, or taskkill.exe. This behavior is often indicative of malicious installation scripts attempting to perform discovery or terminate security processes while remaining stealthy.
Detects indicators of the ProRAM malware dropper, specifically identifying the download of 'sideload.exe' from an external IP or the presence of file artifacts related to its staging process in %TEMP% and %LOCALAPPDATA% directories.
Detect built in PowerShell cmdlet Disable-WindowsOptionalFeature, Deployment Image Servicing and Management tool.
Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
The following analytic detects an unusual process execution pattern where a process running from C:\Windows\SysWOW64\ attempts to execute a binary from C:\Windows\System32\. In a typical Windows environment, 32-bit processes under SysWOW64 should primarily interact with 32-bit binaries within the same directory. However, an execution flow where a 32-bit process spawns a 64-bit binary from System32 can indicate potential process injection, privilege escalation, evasion techniques, or unauthorized execution hijacking.
The detection rule identifies an suspicious process named 'msgbox.exe' attempting to interact with browser configuration files ('Secure Preferences') and activity directories ('stomp_ext'), while simultaneously invoking browser processes ('chrome.exe' or 'msedge.exe') with the '--restore-last-session' argument. This behavior is indicative of an adversary attempting to force-load a browser session or hijack browser state, potentially to steal session cookies or credentials.
Detects the creation of a scheduled task containing 'EdgeCore_AutoUpdate' in the command line using either schtasks.exe or Register-ScheduledTask. This pattern is often indicative of persistence mechanisms attempting to masquerade as legitimate update services.
This rule detects the concurrent existence of specific process names (calibre-launcher.dll or wint.exe) and a specific file (SysPr.prx) on a device, combined with network connections to a specific Cloudflare R2 bucket. This pattern is indicative of potential malware activity involving suspicious DLLs, file drop-offs, and communication with remote infrastructure.
This rule detects potential fileless execution by correlating network connections to a known suspicious domain (workers.dev) with subsequent PowerShell activity on the same device. The rule specifically looks for processes executing PowerShell commands involving Base64 decoding, ChaCha20 decryption, or Assembly.Load, occurring within a 10-minute window of the network connection.
This rule detects network connections initiated by non-browser processes to domains commonly associated with software activation tools (e.g., massgrave.dev, activated.win). These domains are frequently used to download scripts or binaries related to unauthorized license activation, which may represent potential security risks or policy violations.
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
Detects the installation or execution of known remote access tools (RMM) from suspicious parent processes (browsers, archives) or from user-writable directories (Temp, Downloads). This behavior is characteristic of initial access and staging activities performed by ransomware operators or Initial Access Brokers (IABs). The rule excludes known IT-managed deployment paths and signed binaries used by the organization.
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
Page 393 of 1870



