Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects unauthorized processes attempting to read sensitive browser credential and session data (e.g., 'Login Data', 'Cookies', 'Local State', 'cookies.sqlite', 'logins.json') located in common browser profile paths. This behavior is highly indicative of information-stealing malware attempting to extract saved passwords and session cookies for account hijacking and 2FA/SSO bypass.
Adversaries may create a domain account to maintain access to victim systems.
Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain..
Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain..
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system.
Office add-ins can be used to add functionality to Office programs
Office add-ins can be used to add functionality to Office programs
Detects the use of the "Get-ADComputer" cmdlet in order to identify systems which are configured for unconstrained delegation.
Adversaries may use to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
Detects the execution of an MSI file using PowerShell and the WMI Win32_Product class
Detects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.
Detects execution and usage of the DSInternals PowerShell module. Which can be used to perform what might be considered as suspicious activity such as dumping DPAPI backup keys or manipulating NTDS.DIT files.
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
Detects scriptblock text keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
Detects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
Detects package installation activities involving potentially compromised TanStack packages during the defined malicious publish window (2026-05-11 to 2026-05-12). The rule monitors common Node.js package managers (npm, pnpm, yarn, bun) and CLI tools for commands attempting to fetch identified affected versions of @tanstack/* libraries.
Detects anomalous outbound network connections from the Grafana MCP (Model Context Protocol) server process to internal private IP address ranges. The rule compares current network activity against a 14-day baseline to filter out known data sources, identifying potentially unauthorized lateral movement or internal network probing via server-side request forgery (SSRF) vulnerabilities.
Detects anomalous outbound network connections from the Grafana MCP (Model Context Protocol) server process to internal private IP address ranges. The rule compares current network activity against a 14-day baseline to filter out known data sources, identifying potentially unauthorized lateral movement or internal network probing via server-side request forgery (SSRF) vulnerabilities.
Detects the SynkLoader RAT by identifying the pythonw.exe process loading a spoofed msvcp150.dll from a specific staging path (\fl\ang\), combined with correlative beaconing activity via repeated network connections to remote endpoints.
The following analytic detects excessive usage of the nslookup application, which may indicate potential DNS exfiltration attempts. It leverages Sysmon EventCode 1 to monitor process executions, specifically focusing on nslookup.exe. The detection identifies outliers by comparing the frequency of nslookup executions against a calculated threshold. This activity is significant as it can reveal attempts by malware or APT groups to exfiltrate data via DNS queries. If confirmed malicious, this behavior could allow attackers to stealthily transfer sensitive information out of the network, bypassing traditional data exfiltration defenses.
Detects incoming HTTP requests to a Caddy web server using the TRACE or TRACK methods. These methods are rarely used in legitimate production traffic and are frequently associated with Cross-Site Tracing (XST) attempts, which can be used to bypass security controls and steal sensitive data such as cookies.
Detects requests for files with names suggesting sensitive content (password, secret, apikey, etc.).
Detects computer-account creation (Event ID 4741) by a non-administrative user, indicative of abuse of the default Machine Account Quota to join unauthorized machine accounts for privilege escalation, as exploited by CISA's red team.
Detects creation or modification of the Faronics Deploy 'ScriptRunner.log' file. This artifact records script execution history and download URLs used by the Faronics Deploy management platform, which can be abused by adversaries for persistence or remote command execution.
Detects creation or modification of the Faronics Deploy 'ScriptRunner.log' file. This artifact records script execution history and download URLs used by the Faronics Deploy management platform, which can be abused by adversaries for persistence or remote command execution.
Page 438 of 1870







