Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects attempts of decoding a base64 Gzip archive in a PowerShell script. This technique is often used as a method to load malicious content into memory afterward.
Adversaries may manipulate accounts to maintain access to victim systems.
Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups
Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups
Detect malicious GPO modifications can be used to implement many other malicious behaviors.
Detect adversaries enumerate sensitive files
Detects technique used by MAZE ransomware to enumerate directories using Powershell
Adversaries may abuse the Windows command shell for execution.
The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems.
The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands.
Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops.
Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple system
The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems.
The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands.
Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops.
Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple system
Detects inline execution of PowerShell code from a file
Detects EDR or JVM stack-trace or exception telemetry indicating the invocation of insecure deserialization methods associated with Log4jLogEvent$LogEventProxy, such as marshalledMessage.get() or MarshalledObject.get(). This pattern is indicative of potential exploitation attempts leveraging vulnerable Log4j libraries for remote code execution.
Detects the creation or execution of scheduled tasks that involve files located within the 'C:\ProgramData\USOShared\Logs' directory. This directory path is often used by adversaries to stage malicious batch files (e.g., a.bat, c.bat) and establish persistence via Windows Task Scheduler.
Detects the execution of the hacktool Rubeus using specific command line flags
Detects the execution of SOAPHound, a .NET tool for collecting Active Directory data, using specific command-line arguments that may indicate an attempt to extract sensitive AD information.
Detects scheduled task creations or modification on a suspicious schedule type
Detects PEEP Secure Preferences integrity-hash forgery (protection.macs/super_mac) and known PEEP persistence scripts (patch_secure_prefs.ps1, install_silent.ps1, force_enable.ps1), anchored to actual Chrome/Edge profile paths rather than generic terms like 'protection' or 'developer_mode' that appear in unrelated admin tooling.
Detects PEEP Secure Preferences integrity-hash forgery (protection.macs/super_mac) and known PEEP persistence scripts (patch_secure_prefs.ps1, install_silent.ps1, force_enable.ps1), anchored to actual Chrome/Edge profile paths rather than generic terms like 'protection' or 'developer_mode' that appear in unrelated admin tooling.
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
Detects ESC1-style ADCS certificate enrollment where a requester supplies an arbitrary SAN on a misconfigured template (CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT), enabling impersonation of any account. CISA's red team used this to certify a rogue machine account.
Detects instances where 'TieringEngineService.exe' or 'MsMpEng.exe' (Windows Defender) create, modify, or rename executable, library, or system files within the 'C:\Windows\System32\' directory. This behavior is highly irregular as these processes should not be authoring binaries in protected system folders, and may indicate process masquerading, unauthorized persistence, or defense evasion.
Detects the execution of a Faronics Deploy installer that has been renamed to mimic Adobe-related software. This technique is often used in phishing campaigns to trick users into executing binaries that lead to the silent installation of remote monitoring tools like ScreenConnect.
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, encoded commands using char arrays, and iex) that subsequently initiates multiple or long-running network connections. This behavior is indicative of a remote access trojan, beaconing, or fileless malware downloading additional payloads.
Page 428 of 1870






