Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects artifacts of the winAgent v2.0 Windows implant line, including mod_* modules, WUEngine persistence binaries, and COM/CLSID hijack strings used by AI-assisted implant development
Detects artifacts of the winAgent v2.0 Windows implant line, including mod_* modules, WUEngine persistence binaries, and COM/CLSID hijack strings used by AI-assisted implant development
Detects artifacts of the winAgent v2.0 Windows implant line, including mod_* modules, WUEngine persistence binaries, and COM/CLSID hijack strings used by AI-assisted implant development
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
Detects unauthorized modifications to Active Directory Certificate Services (AD CS) template objects (pKICertificateTemplate) using Windows Event ID 5136. This behavior is indicative of ESC4-style attacks, where an adversary with write access to a certificate template modifies security descriptors, enrollment rights, or sensitive configuration flags (like enabling enrollee-supplied SANs or adding a Client Authentication EKU) to facilitate privilege escalation or persistence.
This rule monitors for specific PowerShell command-line patterns often associated with malicious activity, including 'ClickFix' clipboard-paste lures (using iex/irm with sleep timers), evasion techniques involving pscustomobject/ScriptBlock, and WinHttp COM object usage for stage-2 payload fetching. These patterns are characteristic of adversary attempts to bypass security controls and download secondary implants.
Triggers on any Sysmon "FileExecutableDetected" event, which triggers every time a PE that is monitored by the config is created.
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
Detects a suspicious sequence of activities where PowerShell downloads or extracts specific zip files (node.zip, build.zip) to staging directories, followed by the execution of associated binaries like node.exe, winpty-agent.exe, or winpty.dll from those same locations. This behavior is indicative of an adversary staging and executing tooling within temporary user directories.
Detects a suspicious sequence of activities where PowerShell downloads or extracts specific zip files (node.zip, build.zip) to staging directories, followed by the execution of associated binaries like node.exe, winpty-agent.exe, or winpty.dll from those same locations. This behavior is indicative of an adversary staging and executing tooling within temporary user directories.
Detects periodic screen capture activity performed by Node.js or Electron-based processes, correlated with subsequent outbound network connections to public IP addresses within a short timeframe. This behavior is indicative of the JSCeal malware's surveillance and exfiltration module, where local reconnaissance via screenshotting is followed by data transmission.
This rule detects network connections or DNS queries to known phishing domains (typosquatted Microsoft login domains), DeadDrop Resolver domains, and suspicious HTML payloads served from common CDN/package hosting sites (e.g., unpkg.com, npmmirror.com, cdn.jsdelivr.net, yarnpkg.com). These patterns are indicative of initial access attempts via phishing or the secondary stage of malware C2 communication.
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
Detects modifications to the Windows Registry that disable Microsoft Defender Tamper Protection. Tamper Protection is a security feature that prevents malicious changes to security settings, including the disabling of antivirus and real-time monitoring.
Detects attempts to tamper with Microsoft Windows Defender configuration, specifically by modifying exclusion paths via PowerShell cmdlets (Add-MpPreference, Set-MpPreference), direct registry modifications, or forced Group Policy updates. It also monitors for the disabling of Tamper Protection via registry and the creation of scheduled tasks designed to apply Defender exclusions.
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
Page 403 of 1870



