Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects instances where a non-SYSTEM process attempts to open a handle to winlogon.exe. Since winlogon.exe typically runs as SYSTEM and manages user sessions, unauthorized access to its process handle is often a precursor to credential dumping or token manipulation attacks aimed at escalating privileges to SYSTEM.
Detects the registration of a new scheduled task occurring within a network logon session (LogonType 3). This behavior is characteristic of lateral movement techniques where attackers use remote service execution tools (such as Impacket's atexec or PRTremote) to register and execute tasks on a remote host via SMB/RPC. The rule correlates Windows Security Event 4698 (Task creation) with network logon events and validates the action using Task Scheduler operational logs.
Detects instances where Microsoft Outlook (OUTLOOK.EXE) initiates common living-off-the-land (LotL) binaries that are often abused by malicious attachments or macros to execute secondary commands, such as PowerShell, command prompt, or script host engines.
Detects execution of PowerShell commands that use obfuscated [char[]] hex arrays in conjunction with 'iex' (Invoke-Expression) to run code in memory. This pattern is commonly used by loaders like SynkLoader (cleaner.ps1) to execute scripts while avoiding disk artifacts.
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
Detects Python processes executing common system and network enumeration tools (e.g., net.exe, tasklist.exe, dsquery, Get-ADUser). This activity is indicative of the SynkLoader system profiler module, used to size the victim environment for ransom-value estimation and lateral movement preparation.
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
Page 429 of 1870




