Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects evidence of remote service installation and execution, commonly associated with tools like PsExec, PaExec, and RemCom, or the direct use of Windows administrative shares (ADMIN$, C$) to execute binaries remotely. The rule monitors for process creation events involving known service binary names, service creation attempts, or the execution of binaries staged in administrative network shares.
Detects indicators of Cobalt Strike activity, including the creation of default named pipes, process injection into common LOLBins without legitimate parent processes, and network communication patterns consistent with Cobalt Strike malleable C2 profiles.
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) using either the built-in 'comsvcs.dll' library via 'rundll32.exe' or by requesting specific sensitive process access rights to 'lsass.exe' from unauthorized processes.
This rule detects attempts to steal the Active Directory database (ntds.dit) and associated security files by creating volume shadow copies using native Windows utilities like ntdsutil, vssadmin, or wmic. It also monitors for direct file system access or creation attempts related to these sensitive database files within shadow copy paths.
Detects anomalous Kerberos Ticket Granting Service (TGS) requests from a single user account and IP within a 10-minute window. It specifically flags accounts requesting a high volume of TGS tickets or accessing multiple distinct services, where the tickets use RC4 encryption (0x17), which is a characteristic of Kerberoasting attacks targeting service accounts.
Detects anomalous lateral movement behavior where a single user account authenticates via NTLM (LogonType 3, network logon) to three or more distinct hosts within a 30-minute window, without a preceding interactive logon (LogonType 2). This pattern is a strong indicator of an adversary using captured NTLM hashes to move laterally across a Windows environment.
Detects the abuse of native Windows binaries Regsvr32.exe and Rundll32.exe to execute code from remote sources. Regsvr32 is monitored for 'Squiblydoo'-style execution where scrobj.dll is used to execute remote scriptlets via a URL. Rundll32 is monitored for loading DLLs from remote UNC/WebDAV paths or HTTP URLs, which is a common pattern for proxying malicious code execution to bypass local security controls.
This rule detects potentially malicious behavior in package manager post-install scripts (npm, pip). It monitors for child processes like shells, network utilities (curl, wget), or command-line arguments indicative of credential harvesting (e.g., accessing .ssh, .aws/credentials, environment variables) initiated by package management processes.
Detects the physical connection of unauthorized IP-KVM devices (e.g., PiKVM) to corporate endpoints, which could be used for remote control via HDMI capture and USB HID emulation. This detection monitors Plug and Play (PnP) events for specific device descriptors and hardware identifiers commonly associated with remote access hardware.
Detects suspicious outbound HTTPS POST traffic to major generative AI API endpoints (OpenAI, Anthropic, Google) originating from scripting hosts like powershell.exe or python.exe. The detection is triggered by either unusually large outbound payload sizes or the use of unauthorized scripting tools, which is indicative of data exfiltration using AI infrastructure as a relay.
Detects suspicious PowerShell command execution patterns commonly associated with malicious activities, including base64-encoded commands, download cradles used to fetch external content, and various obfuscation techniques like character concatenation or backtick escaping to hide malicious intent.
Detects the creation of a remote service (Event ID 7045 or 4697) on a Windows host shortly after a remote SMB logon. The detection specifically looks for service binary paths associated with well-known lateral movement tools like PsExec (PSEXESVC), the ADMIN$ network share, or randomized executable names within the Windows Temp directory, which are common artifacts left by tools such as Impacket psexec.py and CrackMapExec.
This rule detects suspicious NTLM network logon events (Logon Type 3) involving privileged accounts that do not have corresponding Kerberos authentication events (4768/4769) in the preceding hour. The detection specifically triggers when a single account logs into two or more distinct hosts within a 15-minute window, which is indicative of lateral movement using compromised credentials or Pass-the-Hash techniques.
This rule detects potentially malicious PowerShell activity by identifying common obfuscation patterns, including encoded commands (Base64), IEX (Invoke-Expression) download cradles, and execution with hidden windows. It triggers when multiple suspicious flags are present or when an unusually long encoded blob is identified in script blocks, command lines, or process arguments.
This rule detects the use of forged Kerberos Ticket-Granting Tickets (Golden Tickets), which are typically generated by abusing the KRBTGT account's NTLM hash. The rule monitors Windows Event IDs 4768 and 4769 for anomalies including excessively long ticket lifetimes (common in Mimikatz outputs), evidence of tickets used post-KRBTGT reset, or tickets issued for accounts that do not exist in the environment.
This rule detects network beaconing behavior consistent with Cobalt Strike's default malleable C2 profiles. It monitors HTTP GET and POST requests for specific URI patterns commonly used by default Cobalt Strike configurations and triggers when multiple such requests are observed from a single host over a 15-minute window.
This rule detects potential process injection or process hollowing attempts by correlating Sysmon Event ID 10 (ProcessAccess) events indicating process memory modification permissions (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) with subsequent Sysmon Event ID 8 (CreateRemoteThread) events targeting the same process. This behavior is indicative of an adversary injecting malicious code into a legitimate host process (e.g., svchost.exe, explorer.exe).
Detects the use of legitimate Windows administrative tools (vssadmin, wmic, wbadmin, bcdedit, sc, net) to delete volume shadow copies, clear backup catalogs, disable boot recovery options, or stop critical backup and system services. This behavior is highly characteristic of ransomware activity aiming to prevent data restoration and system recovery.
Detects instances where common scripting engines like Python or Node.js are used to spawn command shells (CMD, PowerShell, or Bash) followed by the execution of suspicious commands commonly associated with reconnaissance, file exfiltration, or lateral movement.
Detects potential exploitation of Active Directory Certificate Services (AD CS) misconfigurations (specifically ESC1, involving client-auth EKU and enrollee-supplies-subject). The rule correlates certificate issuance events (4886, 4887, 4888) involving sensitive templates or suspicious subject alternative name (SAN) mismatches with subsequent Kerberos PKINIT authentication (4768) events using the issued certificate.
Detects the clearing of Windows Event Logs via wevtutil, PowerShell, or registry modification, occurring within one hour of a remote interactive or network logon event on the same host. This pattern is indicative of anti-forensic activity often performed following lateral movement or prior to destructive actions like ransomware deployment.
Page 40 of 1870
