Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule monitors DNS queries and network connection events for interactions with a list of domains associated with the Kali365 infrastructure. It flags activity by identifying both direct matches and subdomains associated with 'ssengineers.com' and 'clientengagenow.de', often used in phishing or C2 communications.
Detects the creation, modification, or renaming of PHP files within the 'wp-content/uploads' directory of a WordPress installation. This pattern is commonly indicative of an attacker uploading a web shell to maintain persistence or execute arbitrary code on a compromised web server.
Detects the creation or renaming of a .pdf file in the root directory followed closely (within 300 seconds) by the creation or renaming of a .vhd (Virtual Hard Disk) file on the same device. This pattern may indicate the use of malicious PDF documents as a decoy or delivery mechanism to initiate the mounting or dropping of virtual disk images for payload execution or data staging.
Detects a DCSync (directory replication) request targeting the krbtgt account, which yields the key material needed to forge Golden Tickets and impersonate any domain user. CISA's red team DCSynced krbtgt early in its Active Directory compromise (AA26-237A).
Detects token duplication/impersonation targeting winlogon.exe to obtain SYSTEM privileges (SeDebugPrivilege abuse, DuplicateToken, SetTokenInformation to Untrusted integrity)
This detection identifies attempts to create or modify Windows Quality of Service (QoS) policy registry entries under:
HKLM\SOFTWARE\Policies\Microsoft\Windows\QoS
where the configured QoS policy references Microsoft Defender for Endpoint components, including SenseIR, MsSense, WinDefend, or MsMpEng. Such modifications may be indicative of the EDRChoker technique, which abuses Windows QoS policies to throttle network bandwidth or degrade communications associated with Endpoint Detection and Response (EDR) solutions, potentially impacting security monitoring and telemetry collection.
The query captures registry modifications targeting these security-related binaries and provides visibility into the initiating user account, process, command line, and parent process responsible for the change. This activity should be validated to determine whether it was performed as part of legitimate system administration or represents an attempt to impair endpoint protection capabilities.
HKLM\SOFTWARE\Policies\Microsoft\Windows\QoS
where the configured QoS policy references Microsoft Defender for Endpoint components, including SenseIR, MsSense, WinDefend, or MsMpEng. Such modifications may be indicative of the EDRChoker technique, which abuses Windows QoS policies to throttle network bandwidth or degrade communications associated with Endpoint Detection and Response (EDR) solutions, potentially impacting security monitoring and telemetry collection.
The query captures registry modifications targeting these security-related binaries and provides visibility into the initiating user account, process, command line, and parent process responsible for the change. This activity should be validated to determine whether it was performed as part of legitimate system administration or represents an attempt to impair endpoint protection capabilities.
Detects the execution of 'conhost.exe' with command-line arguments '--headless' and 'cmd' initiated by 'svchost.exe' as part of a scheduled task. The command executes from user-writable directories such as AppData, ProgramData, or Temp, which is a common pattern for fileless or staged payload execution initiated by malicious scheduled tasks.
Detects common SQL injection attack patterns such as UNION SELECT, OR 1=1, DROP TABLE, and others within the request URI of Caddy web server logs.
This rule monitors for the execution of Node.js processes involving a file named 'parser.js' and a component or argument referred to as 'ldata'. This behavior is characteristic of specific application workflows, but when observed as a standalone or unusual process, it may indicate unauthorized script execution or the activity of a malicious node-based tool.
Detects the invocation of the AppInstaller executable to install .msix packages, often used in software installation or malicious delivery scenarios involving application deployment.
This rule detects unauthorized modifications to browser search provider settings in the Windows Registry, targeting keys associated with Chrome and Microsoft Edge search configuration. This activity is often indicative of browser hijacking or search engine redirection campaigns, such as the NinjaMare malware.
This rule detects the execution of processes or network connections that impersonate 'WhatsApp' or 'Instagram' companion applications. It identifies specific file names and process command lines that mimic these applications, often associated with browser-launched or malicious payloads, and monitors for associated network traffic directed toward suspicious endpoints like herokuapp domains.
Detects a specific evasion behavior associated with the NinjaMare malware, where a process idles for at least 7 minutes before moving its window to off-screen coordinates during automated mouse or keystroke input, followed by restoring the window to its original position.
This rule detects outbound connections from internal devices to domains and IP addresses linked to the “SysScan” fake Microsoft security scanner campaign. These connections may indicate exposure to malicious infrastructure used for tricking victims into disabling legitimate antivirus solutions, as reported in recent threat intelligence.
Detects the use of the Windows 'copy /b' command to join multiple files into a single executable, specifically targeting patterns where document files are merged with a binary named 'Windowsupdate.exe'. This technique is often used to reassemble malicious payloads by combining split components or masquerading malicious content within seemingly benign file operations in temporary user directories.
Detects mass LDAP enumeration queries consistent with a modified BloodHound collector scraping AD users, computers, groups, and GPO/ACL data — customized by CISA's red team to evade static EDR signatures.
Detects process execution shortly after a user clicks a malicious link delivered via spearphishing email, indicating successful initial-access payload execution.
Detects the execution of known screen capture and sniping tools (such as SnippingTool, Greenshot, ShareX, OBS, etc.) when initiated from potentially suspicious user-controlled directories like AppData, Temp, or Downloads. This behavior may indicate an attempt to capture sensitive desktop information or credentials.
This rule detects the loading of specific, known-vulnerable kernel drivers (based on their SHA256 hashes) when triggered by administrative command-line utilities such as cmd.exe or powershell.exe. This behavior is highly characteristic of 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, where adversaries exploit vulnerabilities in legitimate, signed drivers to gain elevated (often SYSTEM or kernel) privileges.
This rule detects the termination of critical security software processes (e.g., antivirus agents) by a process that has recently acquired SeDebugPrivilege. This behavior is indicative of a malicious actor attempting to disable endpoint security controls to evade detection.
Detects modifications to Windows Defender registry keys responsible for exclusions. Specifically monitors when paths or processes associated with potentially suspicious locations (like C:\Drivers) or common system binaries (VSSVC.exe, ctfmon.exe, C:\Windows\System32) are added to the Defender exclusion list. This is a common technique used by attackers to hide malicious files or activity from antivirus scanning.
Page 436 of 1870










