Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects an internal/compromised mailbox sending phishing-style email to multiple employees, the technique CISA's red team used to gain initial workstation access via a trusted internal sender.
This rule detects potential data exfiltration by monitoring write activity to external USB storage devices. It identifies scenarios where a high number of files (more than 25) or a significant total volume of data (more than 100MB) is written to a connected USB device within a short timeframe.
Detects the execution or initiation of a process named 'PrettyPrague.exe' while running with SYSTEM level privileges (AccountSid: S-1-5-18) from directories associated with Avast antivirus software. This activity is indicative of potential privilege escalation or malicious activity masquerading within legitimate security software paths.
This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
Detects instances where the OneDrive sync client process creates files on drives other than the system drive (e.g., D: drive and beyond). This pattern is often used to identify potentially suspicious file synchronization activities or the use of secondary storage locations that may deviate from baseline OneDrive configurations.
Detects repeated, non-interactive requests to the Google Sheets Visualization API (gviz/tq) originating from common web browsers. This pattern is indicative of a malicious browser extension attempting to reconstruct or reinject payloads when a user visits specific targeted websites.
Detects a multi-stage browser-based web skimming attack. The rule identifies a specific sequence of network activity: a device fetching an obfuscated loader script from 'paste.sh', followed by retrieving payload fragments from the 'Google Sheets Visualization API', and concluding with network interactions with crypto-transaction services 'SwapZone.io' or 'SimpleSwap.io', characteristic of a browser-based wallet-drainer campaign.
Detects a multi-stage browser-based web skimming attack. The rule identifies a specific sequence of network activity: a device fetching an obfuscated loader script from 'paste.sh', followed by retrieving payload fragments from the 'Google Sheets Visualization API', and concluding with network interactions with crypto-transaction services 'SwapZone.io' or 'SimpleSwap.io', characteristic of a browser-based wallet-drainer campaign.
This rule detects potential web skimmer activity where a user's browser performs a network connection to known payload delivery hosts (e.g., paste.sh or Google Sheets API) followed by a clipboard modification event on the same device within a one-hour window. This behavior is consistent with malicious scripts attempting to replace copied cryptocurrency wallet addresses with an attacker-controlled address.
Page 418 of 1870




