Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the presence of GoCaracal, a Go-based Remote Access Trojan (RAT) attributed to the Dark Caracal threat group, based on unique strings and function names indicative of its implant capabilities, including shellcode injection and system discovery.
Detects malicious markdown files (SKILL.md) that impersonate agent instruction files. These files contain hidden-content constructs (like CSS display:none, HTML comments, or invisible Unicode characters) combined with common command execution patterns (like curl, wget, or PowerShell encoded commands), characteristic of infostealer campaigns targeting AI agent platforms.
Detects instances of DLL side-loading where common application helper binaries (ClaudeDesktop.exe or JetBrains) load libcef.dll from untrusted, user-writable directories such as Downloads, Temp, or AppData. This behavior is indicative of the Claude FakeAgent campaign, which leverages side-loading for payload deployment.
This rule detects the termination of critical security software processes (e.g., antivirus agents) by a process that has recently acquired SeDebugPrivilege. This behavior is indicative of a malicious actor attempting to disable endpoint security controls to evade detection.
This rule detects potential tampering with the Huorong security product by monitoring for specific process names (HipsTray.exe, HipsMain.exe, HipsDaemon.exe, wsctrlsvc.exe, TrafficProt.exe) interacting with suspicious API calls or command lines indicative of token privilege manipulation, service blinding, or security product disabling/downgrade.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
Detects the suspicious execution of a file named 'Windowsupdate.exe' located in 'AppData\Local' that is invoked via a command containing 'copy' and '/b'. This behavior is indicative of an attacker attempting to copy or stitch binary files using a masqueraded system process name to evade detection.
Detects the execution of VBS scripts (wscript.exe or cscript.exe) that interact with the Windows Startup folder to create shortcuts. This behavior is associated with persistence mechanisms where malicious scripts create masqueraded shortcuts (e.g., SecurityHealth, OneDriveUpdate) in the user's Startup folder, often using hidden attributes to evade detection.
This rule monitors for web server exploit attempts (indicated by patterns like JNDI lookups or SQL injection sequences in URI/cookie data) that correlate with a surge in server-side errors (400+ status codes) and subsequent anomalous process creation or outbound network connections from the web server process.
This rule monitors web server logs (IIS, W3C, and Azure Application Gateway) for incoming traffic that matches known malicious or automated vulnerability scanners, as well as requests for common system fingerprinting paths (such as /server-status or /.git/config). The rule aggregates these hits by source IP address to identify potential active reconnaissance or vulnerability scanning attempts.
This rule monitors for active reconnaissance or scanning behavior by detecting a single source IP interacting with a high number of distinct ports/hosts within a short time frame (NetworkScan) or accessing a high number of distinct URI paths/404 errors (WebContentScan).
Surfaces Silverfort-detected incidents excluding ImpossibleTravel (high FP rate from VPN and mobile users, better covered by XSIAM Analytics UEBA)
Detects a PowerShell in-memory loader pattern that derives an AES key using Rfc2898DeriveBytes, decrypts an encrypted payload using System.Security.Cryptography.Aes, verifies the content with SHA256, and executes the decrypted code in-memory via [System.Management.Automation.ScriptBlock]::Create. This technique is often used to bypass file-based security controls by executing stage-two payloads directly in memory.
This rule detects scenarios where the 'MpDefenderCoreService.exe' process or a process attempting to masquerade as it loads 'mpclient.dll' from a directory path outside of the standard Windows Defender installation folders. This behavior is highly indicative of an adversary masquerading as a legitimate Windows Defender service or attempting to hijack a security-related process to evade detection.
Detects the execution of PowerShell with encoded commands, a common technique used by attackers to obfuscate malicious scripts and evade detection.
Detects suspicious child process creation (e.g., cmd.exe, powershell.exe) originating from Java applications where the command line contains indicators of deserialization vulnerabilities (e.g., FilteredObjectInputStream, Log4jLogEvent). This pattern is often associated with exploitation of Java applications to gain remote code execution.
Detects instances where Windows Defender Antivirus, real-time protection, or associated security features have been explicitly disabled or modified on Windows endpoints. This is a common indicator of defensive evasion during an attack lifecycle.
Detects an executable loading an unexpected DLL, indicative of DLL side-loading used to execute a payload while evading static EDR signatures, as observed in CISA's red team engagement.
Detects the execution of PowerShell with obfuscated parameters such as '-WindowStyle Hidden' and '-ExecutionPolicy Bypass' in combination with network-related cmdlets (Invoke-WebRequest) or process manipulation (Start-Process). It also checks for references to common temporary file paths or 'main.exe', often indicative of malicious script execution or payload staging. The rule also includes a filter to identify if the process was initiated by common WSL or Node.js related processes.
Detects when a rule has been added to the Windows Firewall exception list
Detects the addition of suspicious file names or known potentially unwanted program artifacts to Windows Run registry keys, often used for persistence. The rule correlates registry modifications with potential installer process activity.
Page 442 of 1870










