Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects evidence of PowerShell AMSI (Antimalware Scan Interface) bypass attempts, including memory patching of amsiContext, usage of known malicious RC4 keys, or reflection-based tampering with AmsiUtils. These techniques are commonly used by attackers to disable AMSI scanning capabilities and execute malicious scripts undetected.
Detects network connection attempts to specific external domains associated with suspicious JavaScript payloads. The rule filters for specific file paths (e.g., mpackage.js, bsc-loader.js) linked to known malicious or suspicious URL patterns on cdn.claritydelivr.com, rcrsinnovations.com, konverto.in, and cdn.api-middle-connect.com, which may indicate C2 beaconing or malware infection.
Detects evidence of PowerShell AMSI (Antimalware Scan Interface) bypass attempts, including memory patching of amsiContext, usage of known malicious RC4 keys, or reflection-based tampering with AmsiUtils. These techniques are commonly used by attackers to disable AMSI scanning capabilities and execute malicious scripts undetected.
This rule identifies potential command and control (C2) activity by correlating DNS over HTTPS (DoH) requests initiated by non-browser or unsigned processes with subsequent network connections to a known malicious C2 domain (gw.proxyvector.cc) within a 15-minute window.
Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
Detects network connection attempts to specific external domains associated with suspicious JavaScript payloads. The rule filters for specific file paths (e.g., mpackage.js, bsc-loader.js) linked to known malicious or suspicious URL patterns on cdn.claritydelivr.com, rcrsinnovations.com, konverto.in, and cdn.api-middle-connect.com, which may indicate C2 beaconing or malware infection.
Detects the creation or modification of specific dropper/loader files and service worker registration within WordPress directory structures (wp-content/plugins, wp-content/themes, wp-content/uploads). These files are often associated with the injection of malicious scripts (e.g., on-chain resolvers) to facilitate drive-by compromises by site visitors.
Detects evidence of PowerShell AMSI (Antimalware Scan Interface) bypass attempts, including memory patching of amsiContext, usage of known malicious RC4 keys, or reflection-based tampering with AmsiUtils. These techniques are commonly used by attackers to disable AMSI scanning capabilities and execute malicious scripts undetected.
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
Detects text/report artifacts (markdown, JSON, plain text) produced by an autonomous AI-driven vulnerability research pipeline that decompiles binaries, traces cross-references, hypothesizes memory-safety flaws, and generates/debugs proof-of-concept exploits
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
Page 402 of 1870

