Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
This rule detects potential Kerberoasting activity by monitoring Kerberos Service Ticket requests (Event IDs 4768 and 4769) that utilize the weak RC4 encryption type (0x17). The rule filters for non-computer account activity and specific suspicious Ticket Options that are commonly associated with tool-based Kerberoasting attacks.
Detects attempts to dump credentials from the Local Security Authority Subsystem Service (LSASS) process memory using common tools like Mimikatz, Procdump, or built-in system utilities such as comsvcs.dll or command-line arguments indicating memory dump operations.
Detects potentially malicious PowerShell command-line activity by identifying patterns indicative of obfuscation, fileless execution, AMSI bypass, and downloading/executing remote payloads. The rule flags instances where long command lines are used with encoded flags, base64 decoding logic is paired with execution primitives, explicit AMSI bypass attempts, or combinations of encoded commands with web requests or hidden windows.
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, powershell, diskshadow) to delete volume shadow copies or backup catalogs. This activity is commonly associated with ransomware operations intended to inhibit system recovery.
This rule identifies potential command and control (C2) beaconing activity by detecting periodic, low-jitter outbound network connections. It analyzes network logs to find connections to external IP addresses that maintain a consistent frequency over a period of time, specifically flagging hosts that demonstrate repetitive traffic patterns with low variation (jitter). The rule further filters by identifying 'rare' destinations, focusing on remote IPs that have been connected to by three or fewer hosts within the environment, which is a common indicator of targeted C2 infrastructure.
Detects potential Pass-the-Hash (PtH) activity by monitoring for NTLM network logons (Logon Type 3) that are associated with a blank WorkstationName, often indicating spoofing. This pattern is correlated with the assignment of special privileges (EventID 4672) to capture scenarios where stolen NTLM hashes are replayed for lateral movement into a system.
Detects Kerberos service ticket requests (EventID 4769) that utilize RC4 encryption (0x17) instead of the more secure AES encryption. Attackers often force RC4-HMAC when requesting service tickets for accounts with Service Principal Names (SPNs) because these tickets are susceptible to offline brute-force attacks to recover service account passwords. This technique is a common precursor to lateral movement and privilege escalation in Active Directory environments.
Detects the execution of rclone.exe or a renamed rclone binary using common command-line arguments (copy, sync, config, --progress). Rclone is a popular tool for ransomware double-extortion, as it allows attackers to exfiltrate data to various cloud storage providers while blending into legitimate network traffic.
Detects a sequence of multiple RDP authentication failures (Event ID 4625, Logon Type 10) from a specific source IP, followed by a successful RDP authentication (Event ID 4624, Logon Type 10) from the same source IP. This pattern indicates a successful credential brute force or password spraying attack against RDP, which is a common initial access vector for ransomware and lateral movement.
Detects potential lateral movement by monitoring for the creation of services associated with PsExec (e.g., PSEXESVC or ADMIN$ share usage), followed by a network connection over SMB (port 445) and the subsequent execution of the corresponding remote process.
Detects a volumetric spike in RPC connection attempts (specifically port 135 followed by Netlogon binding) from a single host to a Domain Controller. This behavior is indicative of the exploit retry mechanism used by Zerologon (CVE-2020-1472) tools, which must attempt the authentication sequence thousands of times due to the low success probability of the all-zero byte ClientCredential.
Detects the creation of suspicious services that are preceded by an administrative SMB share (ADMIN$) connection and a network logon event (Type 3) from the same source. This pattern is commonly used by lateral movement tools (like PsExec) to execute payloads remotely by installing a service, accessing the administrative share to drop the binary, and executing the service.
Detects Kerberos TGT (4768) or TGS (4769) tickets that exhibit anomalous characteristics often associated with forged tickets (e.g., Golden Ticket). The rule flags tickets using weak encryption (RC4-HMAC, legacy DES), tickets requested for stale/disabled accounts, or tickets with lifetimes exceeding standard domain policy thresholds.
This rule identifies potential lateral movement or account compromise by detecting accounts that have performed NTLM network logons or authentication (Events 4624/4776) without corresponding Kerberos pre-authentication or interactive logon events within a 15-minute window. This pattern often indicates the use of stolen credentials (e.g., Pass-the-Hash) to access network resources rather than standard interactive user activity.
Detects potential Pass-the-Hash lateral movement by identifying NTLM network/remote-interactive logons from a single user account across three or more distinct destination hosts within a 15-minute window, correlated with the usage of common credential-dumping tools or commands on the source host.
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Directory Service Access) associated with specific Directory Replication Service (DRS) extended rights GUIDs. The rule identifies accounts attempting to perform replication tasks against a Domain Controller, filtering out events originating from recognized Domain Controllers to isolate unauthorized access.
Detects the creation of a Volume Shadow Copy followed by an attempt to copy the NTDS.dit file from the shadow copy device path. This sequence is a common technique used by attackers to bypass file locks and extract Active Directory credential databases.
Detects usage of the Rclone utility (or renamed binaries) to transfer data to various cloud storage backends (S3, Mega, pCloud, SFTP, WebDAV). The detection correlates this activity with the execution of common archival tools (7-Zip, WinRAR, TAR) within one hour prior to the data transfer, which is a common behavior of adversaries preparing data for exfiltration.
Detects high volumes of TGS-REQ events using RC4 encryption (etype 0x17) originating from a single account within a 10-minute window, excluding known service accounts and computer accounts. This pattern is often indicative of an adversary attempting to harvest service account tickets for offline brute-force cracking.
This rule detects the invocation of rundll32.exe, regsvr32.exe, or mshta.exe with arguments pointing to remote resources (UNC, WebDAV, or HTTP(S) URLs). This pattern is commonly used by attackers to execute remote scriptlets (e.g., .sct, .hta, .dll) for living-off-the-land bypasses or initial staging of malicious payloads, such as the Squiblytwo or Squiblydoo techniques.
Page 43 of 1870

