Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
This rule detects modifications to Group Policy Objects (GPO) or Microsoft Entra (formerly Azure AD) policies that weaken established security controls. For GPO, it monitors Event ID 5136 for changes to security-relevant attributes (e.g., disabling firewall or real-time monitoring) in Active Directory. For Entra, it monitors audit logs for administrative operations that reduce security posture, such as disabling MFA, lowering authentication trust, or deleting Conditional Access policies. It includes filters to exclude legitimate, documented change management activities.
This rule detects modifications to Group Policy Objects (GPO) or Microsoft Entra (formerly Azure AD) policies that weaken established security controls. For GPO, it monitors Event ID 5136 for changes to security-relevant attributes (e.g., disabling firewall or real-time monitoring) in Active Directory. For Entra, it monitors audit logs for administrative operations that reduce security posture, such as disabling MFA, lowering authentication trust, or deleting Conditional Access policies. It includes filters to exclude legitimate, documented change management activities.
Detects the placement of potentially malicious executable or script files onto a network share followed by the execution of that specific file path from a different host within a short timeframe. This behavior is indicative of lateral movement using tainted shared content.
Detects the placement of potentially malicious executable or script files onto a network share followed by the execution of that specific file path from a different host within a short timeframe. This behavior is indicative of lateral movement using tainted shared content.
Detects the placement of potentially malicious executable or script files onto a network share followed by the execution of that specific file path from a different host within a short timeframe. This behavior is indicative of lateral movement using tainted shared content.
Detects potential remote service session hijacking by monitoring for RDP session ID reuse by a different user or unauthorized SSH session reattachment (e.g., tmux/screen hijacking). It correlates logon events with process execution to identify instances where an existing session is accessed by an account other than the original owner, while excluding legitimate service/support account activity.
Detects potential remote service session hijacking by monitoring for RDP session ID reuse by a different user or unauthorized SSH session reattachment (e.g., tmux/screen hijacking). It correlates logon events with process execution to identify instances where an existing session is accessed by an account other than the original owner, while excluding legitimate service/support account activity.
Detects potential remote service session hijacking by monitoring for RDP session ID reuse by a different user or unauthorized SSH session reattachment (e.g., tmux/screen hijacking). It correlates logon events with process execution to identify instances where an existing session is accessed by an account other than the original owner, while excluding legitimate service/support account activity.
Detects commandline keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
This rule monitors network traffic from internal devices and security logs for communication with a curated list of known malicious or suspicious scanner IP addresses, indicating potential reconnaissance or probing activity by external actors.
Detects anomalous remote interactive or network logons where the specific account and remote host/IP combination has not been observed in the previous 14 days. The rule correlates these new login events with subsequent process execution on the destination host within a short window (5 minutes) to identify potential lateral movement where an adversary uses valid credentials to log in and immediately execute commands.
Detects anomalous remote interactive or network logons where the specific account and remote host/IP combination has not been observed in the previous 14 days. The rule correlates these new login events with subsequent process execution on the destination host within a short window (5 minutes) to identify potential lateral movement where an adversary uses valid credentials to log in and immediately execute commands.
Detects anomalous remote interactive or network logons where the specific account and remote host/IP combination has not been observed in the previous 14 days. The rule correlates these new login events with subsequent process execution on the destination host within a short window (5 minutes) to identify potential lateral movement where an adversary uses valid credentials to log in and immediately execute commands.
This rule detects potentially malicious activity associated with removable media (USB drives) by identifying two distinct patterns: first, the creation of an 'autorun.inf' file on a removable drive followed by the execution of a script or executable from that same drive shortly after. Second, it identifies executables appearing on removable media that are launched across multiple distinct hosts within a one-hour window, which may indicate worm-like spreading or mass-malware distribution via portable storage.
This rule detects potentially malicious activity associated with removable media (USB drives) by identifying two distinct patterns: first, the creation of an 'autorun.inf' file on a removable drive followed by the execution of a script or executable from that same drive shortly after. Second, it identifies executables appearing on removable media that are launched across multiple distinct hosts within a one-hour window, which may indicate worm-like spreading or mass-malware distribution via portable storage.
This rule detects potentially malicious activity associated with removable media (USB drives) by identifying two distinct patterns: first, the creation of an 'autorun.inf' file on a removable drive followed by the execution of a script or executable from that same drive shortly after. Second, it identifies executables appearing on removable media that are launched across multiple distinct hosts within a one-hour window, which may indicate worm-like spreading or mass-malware distribution via portable storage.
Detects anomalous authentication behavior where a user account utilizes the same authentication session (LogonId) or material to authenticate across multiple distinct destination hosts in a short timeframe. This rule monitors for both NTLM (Type 3) and Kerberos (TGS/TGT) events, which are indicative of lateral movement techniques such as Pass-the-Hash or Pass-the-Ticket.
Detects anomalous authentication behavior where a user account utilizes the same authentication session (LogonId) or material to authenticate across multiple distinct destination hosts in a short timeframe. This rule monitors for both NTLM (Type 3) and Kerberos (TGS/TGT) events, which are indicative of lateral movement techniques such as Pass-the-Hash or Pass-the-Ticket.
Detects anomalous authentication behavior where a user account utilizes the same authentication session (LogonId) or material to authenticate across multiple distinct destination hosts in a short timeframe. This rule monitors for both NTLM (Type 3) and Kerberos (TGS/TGT) events, which are indicative of lateral movement techniques such as Pass-the-Hash or Pass-the-Ticket.
Detects potential abuse of MSBuild.exe or DotNet.exe as a proxy for executing arbitrary code. The rule identifies processes executing MSBuild or specific DotNet CLI operations (build, publish, test, pack) that do not originate from expected binary names, indicating a possible attempt to bypass application execution defenses using trusted developer utilities.
Page 407 of 1870



