Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
The following analytic detects .cab files being written to disk.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on events where the file name is '*.cab' and the action is 'write'.
This activity can be significant as .cab files can be used to deliver malicious payloads, including embedded .url files that execute harmful code.
If confirmed malicious, this behavior could lead to unauthorized code execution and potential system compromise.
Analysts should review the file path and associated artifacts for further investigation.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on events where the file name is '*.cab' and the action is 'write'.
This activity can be significant as .cab files can be used to deliver malicious payloads, including embedded .url files that execute harmful code.
If confirmed malicious, this behavior could lead to unauthorized code execution and potential system compromise.
Analysts should review the file path and associated artifacts for further investigation.
Detects the use of the 'netsh wlan show profile' command with the 'key=clear' argument, which is used to display the plaintext passwords of stored WiFi profiles on a Windows system.
This rule identifies devices in the environment that are running software identified as vulnerable to CVE-2026-62890. It aggregates the affected device names along with the associated software names, versions, and vulnerability severity levels.
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
Detects suspicious service installation patterns involving WmiPrvSE, common in lateral movement techniques.
Detects file creation, modification, or renaming in System32 by TieringEngineService.exe or MsMpEng.exe within a short time frame.
Detects file creation, modification, or renaming in System32 by TieringEngineService.exe or MsMpEng.exe within a short time frame.
Detects file creation, modification, or renaming in System32 by TieringEngineService.exe or MsMpEng.exe within a short time frame.
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
Detects remote service creation consistent with PsExec-style lateral movement by correlating network logons (Type 3) with subsequent service installations.
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
Detects NTLM network logons (NtLmSsp) for accounts that may have been targets of certificate-based identity abuse (e.g., ESC1). Attackers often leverage this technique to extract NTLM hashes from PKINIT TGT PACs and subsequently utilize Pass-the-Hash for lateral movement within the network.
Detects suspicious DNS queries to external service interaction domains often used for out-of-band interactions after successful RCE
This is something I have seen many times during my years working in cybersecurity: users download software with a filename they recognize and trust, but the file behind that name can be something completely different.
Monitoring the filename is not enough. Monitoring the hash is better, but legitimate software changes constantly: new version, new SHA256, another hash to validate and maintain. So I started thinking about how AI agents could help us here — not by deciding what is malicious, but by doing the repetitive work for us.
For this research, I built an AI-maintained baseline of legitimate software and used it from KQL to hunt two different scenarios:
🎯 Known filename + Unknown hash + Untrusted download source
Monitoring the filename is not enough. Monitoring the hash is better, but legitimate software changes constantly: new version, new SHA256, another hash to validate and maintain. So I started thinking about how AI agents could help us here — not by deciding what is malicious, but by doing the repetitive work for us.
For this research, I built an AI-maintained baseline of legitimate software and used it from KQL to hunt two different scenarios:
🎯 Known filename + Unknown hash + Untrusted download source
Page 420 of 1870






