Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
Detects authentication to a web application using default/built-in account credentials followed by outbound mail sent from an internal address — the technique CISA's red team used to send phishing email from a trusted internal identity.
Detects access to files containing cleartext credentials on an administrative workstation, followed by their use to authenticate to a sensitive business system — the initial-access path CISA's red team used against SBS 1.
Shows all Kerberos authentication activity on domain controllers - TGT requests, TGS requests, and pre-auth failures (4768/4769/4771). Good for hunting credential attacks, AS-REP roasting, weak encryption usage, and account lockout troubleshooting.
Detects the use of PowerShell (Invoke-WebRequest or Invoke-RestMethod) to download files to the AppData directory, followed by the execution of a file using a 'token-raw' argument. This pattern is often associated with malicious payload delivery and execution.
Detects the execution of known Remote Monitoring and Management (RMM) and remote access tools. The rule specifically flags these tools when they are executed from high-risk directories such as AppData, Temp, Downloads, or ProgramData, which is a common indicator of unauthorized installation or persistence efforts by an adversary.
The following analytic detects the execution of JScript using the cscript.exe process.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry.
This behavior is significant because JScript files are typically executed by wscript.exe, making cscript.exe execution unusual and potentially indicative of malicious activity, such as the FIN7 group's tactics.
If confirmed malicious, this activity could allow attackers to execute arbitrary scripts, leading to code execution, data exfiltration, or further system compromise.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry.
This behavior is significant because JScript files are typically executed by wscript.exe, making cscript.exe execution unusual and potentially indicative of malicious activity, such as the FIN7 group's tactics.
If confirmed malicious, this activity could allow attackers to execute arbitrary scripts, leading to code execution, data exfiltration, or further system compromise.
Detects attempts to stop or reconfigure critical Windows security services (such as WinDefend, WscSvc, Sense, and WdNisSvc) using the Service Control Manager (sc.exe) or by modifying service registry keys via reg.exe. This behavior is indicative of an adversary attempting to disable EDR/AV solutions to evade detection.
This rule detects the use of raw sockets by 'ERAAgent.exe' by monitoring for socket I/O control (Ioctl) operations involving 'SIO_RCVALL'. This configuration, often associated with promiscuous mode, allows an application to capture all network traffic received by the network interface, a behavior commonly used by network sniffing tools or malicious implants to intercept sensitive data.
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
Detects behavior where the ERAAgent process writes a file to disk and executes that same file shortly after (within 5 minutes). This pattern is consistent with staged payload delivery, decompression, or assembly often observed in malicious activity, specifically referencing SLEEPWALKER malware patterns.
Page 430 of 1870





