Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects network requests to unpkg.com or npmmirror for 'index.html' files directly under a package path. This behavior deviates from standard package management usage (which typically fetches tarballs or specific JavaScript modules) and is often associated with adversaries using npm packages as hosting infrastructure for phishing landing pages.
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
Detects anomalous outbound network connections from the Grafana MCP (Model Context Protocol) server process to internal private IP address ranges. The rule compares current network activity against a 14-day baseline to filter out known data sources, identifying potentially unauthorized lateral movement or internal network probing via server-side request forgery (SSRF) vulnerabilities.
This rule detects file access, creation, modification, or renaming operations involving sensitive files associated with cryptocurrency wallets (Bitcoin, Electrum, ElectrumSV), game account configurations (Battle.net, Steam, Minecraft), and browser-based cookies (Roblox). The rule filters out legitimate process interactions, identifying suspicious activity from unknown or unauthorized applications potentially attempting to exfiltrate credentials or session tokens.
This rule detects instances where LockAppHost.exe or a variation of it (likely used as a proxy) initiates processes or command-line arguments that interact with Windows services, scheduled tasks, or Windows Defender configurations. This behavior is indicative of an adversary attempting to disable security features, suppress Windows updates, or manipulate system services to evade detection.
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
Detects periodic screen capture activity performed by Node.js or Electron-based processes, correlated with subsequent outbound network connections to public IP addresses within a short timeframe. This behavior is indicative of the JSCeal malware's surveillance and exfiltration module, where local reconnaissance via screenshotting is followed by data transmission.
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
This rule detects suspicious activity associated with JSCeal proxy handlers. It identifies Node.js or Electron processes running from non-standard, user-writable directories (such as AppData, ProgramData, or Temp folders) that actively delete or modify browser cookie files within standard web browser profile paths, often indicative of session hijacking or data tampering.
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
Detects the execution of Terraform commands (init, apply, plan) that interact with the 'registry.coder.com' domain, or direct network connections to the associated infrastructure. This may indicate the use of unauthorized or compromised Infrastructure-as-Code (IaC) modules or malicious supply chain activity involving Terraform configurations.
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
This rule identifies potential DNS tunneling or beaconing activity by detecting an unusually high volume of DNS queries (exceeding 50 requests) made to a specific domain name within a given timeframe. Such patterns are often associated with C2 communication or data exfiltration via the DNS protocol.
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
The detection rule identifies network connections to 'dauntingmoon.online' specifically hitting '/api/verification/init' or '/api/verification/check' paths. It validates that both 'session' and 'link_id' query parameters are present in the request. This pattern is indicative of a specific adversary beaconing or command and control (C2) callback mechanism involving session-based authentication or handshake steps with a remote server.
Detects network connections initiated by common web browsers to a specific LinodeObjects domain or any subdomains within the linodeobjects.com infrastructure, which may indicate command and control communication or data exfiltration via legitimate cloud storage providers.
Detects network connections initiated by common web browsers to a specific LinodeObjects domain or any subdomains within the linodeobjects.com infrastructure, which may indicate command and control communication or data exfiltration via legitimate cloud storage providers.
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
Page 415 of 1870


