Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
Detects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value.
The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts.
When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts.
When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
Detects network activity from infrastructure provisioner tools (Terraform, Coder) or shell processes attempting to connect to suspicious domains (e.g., coder-infra.com) that resemble legitimate infrastructure domains. This activity is indicative of credential theft, specifically targeting OIDC tokens, SSH keys, or authentication tokens during automated provisioning processes.
Detects the execution of Terraform commands (init, apply, plan) that interact with the 'registry.coder.com' domain, or direct network connections to the associated infrastructure. This may indicate the use of unauthorized or compromised Infrastructure-as-Code (IaC) modules or malicious supply chain activity involving Terraform configurations.
Detects the execution of Terraform commands (init, apply, plan) that interact with the 'registry.coder.com' domain, or direct network connections to the associated infrastructure. This may indicate the use of unauthorized or compromised Infrastructure-as-Code (IaC) modules or malicious supply chain activity involving Terraform configurations.
Detects the restoration of files from the defender quarantine
Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services.
Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start.
Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start.
Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
Detects a child process spawned by 'winrshost.exe', which suggests remote command execution through Windows Remote Shell (WinRs) and may indicate potential lateral movement activity.
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information
Detects the use of the 'Pubprn.vbs' Microsoft signed script to execute commands.
The following analytic identifies processes running from %temp% directory file paths. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment.
This rule detects DNS requests to common cloud-based infrastructure providers often used by adversaries for Command and Control (C2) operations, including AWS API Gateway, Azure App Service, Google Cloud Functions, and Cloudflare Workers. These domains are frequently leveraged to host redirectors, beaconing infrastructure, or malicious payloads.
This rule detects the presence of HardBreacher proof-of-concept executables or DLLs containing the string 'SolidSnake.dll'. This identifier is associated with the payload delivery mechanism for a Kaspersky Endpoint Security exploit.
Detects execution of pythonw.exe (windowless Python) from user-writable directories (e.g., AppData, Temp, Downloads) when launched by common parent processes typically associated with initial access or execution, indicative of the SynkLoader C2 malware.
Page 434 of 1870




