Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects unauthorized devices or processes attempting to communicate with the Telegram Bot API (/sendMessage or /sendDocument) and monitors for credential-related terms within the request metadata. This often indicates the use of Telegram as a command-and-control (C2) channel for data exfiltration or credential theft.
Detects unauthorized devices or processes attempting to communicate with the Telegram Bot API (/sendMessage or /sendDocument) and monitors for credential-related terms within the request metadata. This often indicates the use of Telegram as a command-and-control (C2) channel for data exfiltration or credential theft.
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
Detects suspicious service installation patterns involving WmiPrvSE, common in lateral movement techniques.
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
Detects remote service creation consistent with PsExec-style lateral movement by correlating network logons (Type 3) with subsequent service installations.
Detects remote service creation consistent with PsExec-style lateral movement by correlating network logons (Type 3) with subsequent service installations.
Detects post-exploitation persistence artifacts on Windows endpoints consistent with abuse of CVE-2026-18577.
Detects installation of specific suspicious or known helper services, often associated with persistence or proxying.
Detects installation of specific suspicious or known helper services, often associated with persistence or proxying.
Detects a DLL created or modified directly under C:\Windows\System32 that is then loaded into a process within 30 minutes of its creation. This creation-to-load temporal correlation is a durable indicator of a dropped-and-loaded malicious module (as used by the HardBreacher/SolidSnake exploit chain), independent of the DLL's filename. Signer/trust correlation intentionally omitted (DeviceFileCertificateInfo not part of this environment's ingested telemetry).
This rule detects modifications, creation, or renaming of the Windows hosts file located at 'C:\Windows\System32\drivers\etc\hosts'. Adversaries often modify this file to redirect network traffic, facilitate phishing, or prevent security tools from communicating with update or telemetry servers.
Detects the execution of known WinProtector rogueware binaries. These files often present fake 'threat detected' popups to coerce users into paying for fraudulent software and are frequently bundled with other malware, such as Sality.
This rule monitors for suspicious activity targeting security software and host security configurations. It detects the termination of security-related processes using 'taskkill' or service management commands, the disabling of Windows Firewall via 'netsh', and the modification of critical Registry keys related to User Account Control (UAC), Registry editing access, and Task Manager functionality.
Detects malicious activity patterns characteristic of Sality or similar rootkits, which involve disabling endpoint protection mechanisms (AV/Firewall) in conjunction with kernel-mode driver installation or hooking operations to persist and hide malware activity.
This rule detects potential credential and keystroke theft by identifying the installation of a Windows hook (SetWindowsHookEx) followed within 30 minutes by file access to sensitive browser credential stores (Login Data, key4.db, etc.) by the same process on a single device.
Detects the Sality malware secondary loader creating a new thread within the same infected process, a technique known as self-injection, used to execute decrypted payloads. The rule specifically looks for 'CreateRemoteThreadApiCall' events where the initiating process ID matches the target process ID and correlates this behavior with the creation of mutexes associated with the Sality malware family.
This rule detects potentially malicious executables associated with Sality malware that consistently launch shortly after system startup across multiple boot sessions. It correlates boot events with process execution events within a 10-minute window post-startup to identify programs exhibiting persistence behavior across at least two separate boot instances.
Detects a host performing high-volume outbound network scanning (connecting to 10 or more distinct public IP addresses within 15 minutes) followed by the execution of an executable file created in common suspicious directories (AppData, Temp, Downloads, or Users/Public) within a short window (10 minutes after the scan). This pattern is indicative of a compromised host scanning for lateral movement opportunities or propagation targets, followed by the deployment of malicious tooling.
This rule monitors for two indicators of potentially self-propagating malware: the creation of autorun.inf files on removable or network-mapped drives combined with active SMB network connections (suggesting worm propagation), and the rapid creation of multiple unique executable files across multiple devices (suggesting an outbreak or worm activity).
Detects execution and file activity associated with the XRed backdoor, which masquerades as 'Synaptics.exe' by running from the non-standard 'C:\ProgramData\Synaptics\' directory instead of authorized system paths.
Page 398 of 1870


