Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects Microsoft Edge being launched in a headless state with remote debugging enabled, hidden window dimensions, and a specific temporary user data directory naming convention. This pattern is characteristic of the TWINLOOT technique, where an adversary controls a headless browser via the Chrome DevTools Protocol (CDP) to conduct C2 communications and data exfiltration through legitimate Microsoft Graph API endpoints, effectively blending malicious traffic with normal browser activity.
This rule detects the presence of XMRig cryptocurrency mining binaries, including those associated with the MayaBot campaign, by inspecting file contents for characteristic strings, configuration parameters, and executable signatures.
This rule detects a specific and highly suspicious process lineage: pcalua.exe (Program Compatibility Assistant) spawning powershell.exe, which subsequently triggers WmiPrvSE.exe, followed by cmd.exe and finally rundll32.exe. This chain often indicates a sophisticated attempt to bypass security controls by nesting execution through legitimate Windows utilities.
Detects the ERAAgent.exe process creating raw sockets (SOCK_RAW) and enabling promiscuous mode (SIO_RCVALL) on a non-loopback interface while lacking corresponding listening port activity. This behavior is indicative of passive magic-packet sniffing, often associated with the SLEEPWALKER backdoor/trojan.
This rule monitors the execution of the Outlook process (olk.exe) where the command line contains the argument 'upn='. This pattern is often associated with the manual invocation of Outlook components or potential credential manipulation, as user principal names (UPNs) are frequently used in authentication workflows and may be targeted or misused.
Detects the creation of Windows Registry Run keys that masquerade as legitimate Realtek or WinAudio services. These keys point to executables located in user-writable paths such as AppData, Roaming, or Temp, a technique commonly associated with persistence mechanisms for malware like the Chaos ransomware.
Detects behavior associated with BTR Reforged by correlating the creation of a Windows kernel driver (.sys), registration of the same driver through a service ImagePath, and the subsequent loading of that driver into the kernel within a short time window. The detection is behavior-based and does not rely on BTR-specific filenames, hashes, process names, or paths. Tested against BTR Reforged in a Microsoft Defender for Endpoint lab environment.
This rule identifies Windows Server devices, specifically potential Domain Controllers, that are flagged as vulnerable to CVE-2026-27912 (ResetNightmare) and CVE-2026-25177 (KerberLoss). It checks for the absence of the March/April 2026 cumulative updates that address critical Kerberos Change Password and Service Principal Name (SPN) logic flaws.
Detects the loading of 'SolidPDFCreator.dll' from a specific 'C:\ProgramData\IDM\logs\' directory by specific executables often associated with potential malicious activity or masquerading. This behavior is indicative of potential DLL side-loading or execution of masqueraded binaries.
Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Detects usage of "Reflection.Assembly" load functions to dynamically load assemblies in memory
Detect the use of "<" to read and potentially execute a file via cmd.exe
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system
Detects execution of 'BrowserCore.exe' when the initiating (parent) process is not a recognized web browser (msedge.exe, chrome.exe, or firefox.exe). This rule flags potential process masquerading or misuse of the BrowserCore utility, particularly when spawned by command interpreters or the Task Scheduler.
Detects a set of suspicious network related commands often used in recon stages
Detects execution and usage of the DSInternals PowerShell module. Which can be used to perform what might be considered as suspicious activity such as dumping DPAPI backup keys or manipulating NTDS.DIT files.
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
Detects potential web reconnaissance or scanning activity against Microsoft IIS servers. The rule identifies suspicious behavior by monitoring for high frequencies of distinct URI requests, excessive 404 Not Found status codes indicative of path brute-forcing, and the presence of known security scanning user-agents.
Detects instances where PowerShell.exe is launched by a process that has loaded specific Visual C++ Redistributable DLLs (msvcp150.dll or msvcp160.dll). This pattern is often associated with the execution of applications built with Visual Studio 2017/2019 that may be acting as loaders or wrappers for malicious PowerShell scripts.
Detects the execution of the PhishLocker module, a component of the SynkLoader malware. This module is designed to display a fake, full-screen Windows lock-screen overlay to conduct credential phishing. The rule identifies processes exhibiting the 'Main Window' title associated with these malicious DLLs (msvcp150.dll or msvcp160.dll) that are typically used for sideloading.
Detects execution of a PowerShell script named 'rust-setup.ps1' or network connectivity to a specific external IP address (23.254.165.112:443) identified as a stage-2 payload delivery or command-and-control communication in a supply chain attack scenario.
Page 445 of 1870









