Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution or presence of files, processes, or paths associated with the 'SnowKiller' malware or tool, as identified by keyword matching in process event logs.
This rule detects modifications to the security descriptors (ACLs) of sensitive Active Directory objects, specifically targeting additions of powerful rights like GenericAll, GenericWrite, WriteDacl, or ForceChangePassword. Monitoring these changes on privileged objects such as Domain Admins, Enterprise Admins, and Domain Controllers is critical for detecting potential privilege escalation or persistence efforts.
AD CS ESC8 Certificate Request via NTLM
Cortex XDR
Detects Active Directory Certificate Services (AD CS) certificate requests that utilize NTLM authentication rather than Kerberos. This behavior is indicative of potential NTLM relay attacks (ESC8), where an attacker forces a machine account to authenticate to the AD CS web enrollment endpoint via NTLM to obtain a certificate on behalf of that machine.
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
This rule detects the execution of potentially malicious files (executables, scripts) from user-writable directories (Downloads, AppData, Desktop) where the file appears to be related to a ZIP archive recently downloaded or extracted by an archive handler or browser. It correlates process execution events with file creation events from ZIP archives to identify potential user-execution of malicious payloads delivered via ZIP files.
Detects execution of AnyDesk from non-standard directories such as Temp, AppData, or User profile folders, often indicative of unauthorized or portable installation of remote access software.
This rule monitors for three distinct suspicious behaviors on Windows endpoints: the addition of executable files from temporary or user-writable directories to Windows registry run keys for persistence, the creation of repeated hidden log or data files in AppData directories, and unsigned processes accessing browser-related credential storage files.
This rule monitors DeviceNetworkEvents for outbound connections to a list of known malicious or suspicious IP addresses. This activity is indicative of potential command and control (C2) communication or unauthorized data exfiltration.
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
The following analytic identifies public network connections initiated by Living Off the Land Binaries and Scripts (LOLBAS) that rarely require direct outbound network access.
It leverages the Network Traffic data model and focuses on native Windows binaries where any public destination should be investigated and explicitly approved.
This activity may indicate proxy execution, process injection, payload download, command-and-control, or other abuse of trusted binaries to evade security controls.
Keep in mind that some of these binaries, such as Netsh.exe, Gpscript.exe, Wmic.exe, etc., will occasionally communicate with public network resources to perform their intended function.
Exclude said processes from the detection if they are too noisy for your environment.
Join this detection with the Process Execution events to provide context and avoid false positives.
It leverages the Network Traffic data model and focuses on native Windows binaries where any public destination should be investigated and explicitly approved.
This activity may indicate proxy execution, process injection, payload download, command-and-control, or other abuse of trusted binaries to evade security controls.
Keep in mind that some of these binaries, such as Netsh.exe, Gpscript.exe, Wmic.exe, etc., will occasionally communicate with public network resources to perform their intended function.
Exclude said processes from the detection if they are too noisy for your environment.
Join this detection with the Process Execution events to provide context and avoid false positives.
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
Detects known malicious file hashes for GRAYRABBIT delivery chain components: trojanized 7zp.dll loader, encrypted PE loader shellcode, and GRAYRABBIT backdoor core.dll, gated on PE structural validity and filesize
Detects known malicious file hashes for GRAYRABBIT delivery chain components: trojanized 7zp.dll loader, encrypted PE loader shellcode, and GRAYRABBIT backdoor core.dll, gated on PE structural validity and filesize
Detects trojanized 7z.dll loader and encrypted GRAYRABBIT payload components dropped during the UNC3569 exploit chain
Detects trojanized 7z.dll loader and encrypted GRAYRABBIT payload components dropped during the UNC3569 exploit chain
Detects trojanized 7z.dll loader and encrypted GRAYRABBIT payload components dropped during the UNC3569 exploit chain
Page 404 of 1870


