Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
This rule detects modifications to Group Policy Objects (GPO) or Microsoft Entra (formerly Azure AD) policies that weaken established security controls. For GPO, it monitors Event ID 5136 for changes to security-relevant attributes (e.g., disabling firewall or real-time monitoring) in Active Directory. For Entra, it monitors audit logs for administrative operations that reduce security posture, such as disabling MFA, lowering authentication trust, or deleting Conditional Access policies. It includes filters to exclude legitimate, documented change management activities.
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
This rule monitors for scenarios where multiple common GUI applications (such as browsers, explorer, or notepad) are executed in rapid succession (within 2 minutes) from suspicious directories commonly associated with malware staging (e.g., Temp, AppData, or Downloads). This pattern is often indicative of an adversary executing a malicious payload, such as a multi-stage dropper or a file-based installer masquerading as legitimate software.
Detects the creation of new executable files within a directory path containing 'Download'. This behavior is often associated with the delivery of malicious payloads via browser downloads or other file transfer mechanisms, followed by potential user execution.
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
This rule detects the presence or execution of a file named 'GlobalProtect.exe' within the Palo Alto GlobalProtect directory. It focuses on identifying potentially masqueraded or unauthorized binaries by monitoring file events and associated process execution. This pattern is commonly used by attackers to disguise malicious files as legitimate security software to evade detection.
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
Detects the execution of the Windows FTP client (ftp.exe) initiated by command-line interpreters such as cmd.exe, powershell.exe, or wscript.exe, specifically when utilizing the '-s:' flag. This flag is commonly used to provide a text file containing FTP commands, which is a frequent technique for automated file transfers or exfiltration during post-exploitation activities.
Page 426 of 1870




