Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule monitors firewall traffic logs to identify connections directed at managed internal endpoints originating from devices not tracked by the endpoint management system. It flags potential rogue or unauthorized devices performing multi-target reconnaissance or communication across the internal network.
This rule detects the loading of known vulnerable drivers on Windows systems by cross-referencing driver load events with a curated list of vulnerable drivers maintained by LOLDrivers.io. This technique, commonly referred to as 'Bring Your Own Vulnerable Driver' (BYOVD), is frequently used by adversaries to escalate privileges or perform kernel-mode exploitation.
This rule monitors the Windows Application event log for critical Microsoft SQL Server (MSSQL) events. It detects server crashes, access violations, stack overflows, and high-severity (20+) errors. These events often indicate severe database corruption, underlying system instability, or potential exploitation attempts targeting the database engine.
Detects Windows Internet Shortcut (.url) files that contain suspicious lures and direct users to Microsoft device code authentication endpoints (devicelogin), characteristic of ARToken phishing campaigns hosted on anonymous SharePoint shares.
Flags direct registry staging of a Boot Bus Extender service (SERVICE_SYSTEM_START) whose Args value contains ':changelist', bypassing the Service Control Manager, where the driver image lies outside the Defender platform folder or uses a randomized 8-character filename — the SCM-bypass pattern used to stage BTR.sys for boot-time or immediate execution.
This rule monitors network connections for traffic directed towards domains and IP addresses associated with a known malicious campaign distributing fake VPN browser extensions, as identified by Socket.dev. These domains and IPs are used for command and control or malicious communication by the browser extensions.
Detects the botking RAT issuing Shell/ShellX/runscript commands that spawn powershell.exe from an implant-named parent process, matching the backdoor's remote command-execution capability.
This rule detects the creation or modification of scheduled tasks or Windows services that reference 'fl_bridge' in their command line, service configuration, or task properties. This is often associated with persistence or execution mechanisms utilized by specific malware or unauthorized tools.
This rule detects potential DLL side-loading activity where known legitimate executables, typically vulnerable to hijacking, are executed from suspicious directories (such as Temp, Downloads, or ProgramData) and subsequently load associated, potentially malicious DLLs.
This rule detects potential DLL side-loading where 'FineReader.exe' loads the library 'dsp_ippv2_x64.dll'. It joins process creation and image load events to identify if the application was executed shortly before the library was loaded, which is a common indicator of side-loading activities.
Detects the process 'Acrobatlog.exe' loading the DLL 'scansts.dll'. This pattern is frequently observed as a potential DLL side-loading or hijack attempt, where a non-standard or unexpected DLL is loaded by a specific process executable.
Detects Python or PythonW processes loading an illegitimate 'msvcp150.dll' (masquerading as a Visual C++ redistributable) that simultaneously loads the .NET 'System.Management.Automation' assembly. This behavior is indicative of the SynkLoader technique, where a malicious native DLL is used as a bridge to execute PowerShell commands within the memory space of a Python process, bypassing traditional script-based detection.
Detects the creation of a Windows Scheduled Task (Event ID 4698) that uses the 'InteractiveToken' LogonType, where the user specified to execute the task is different from the user who registered the task. This behavior is indicative of potential session hijacking or lateral movement techniques, such as those used by tools like 'atexec' or to facilitate PRT (Primary Refresh Token) theft.
Detects Portable Executable (PE) files that reference or contain the string 'Warden.dll'. This DLL name is associated with the ShieldBreak proof-of-concept (PoC) which attempts to bypass Microsoft Defender by manipulating its defensive processes or environment.
Detects the creation of a 'Report.wer' file, typically associated with Windows Error Reporting (WER), within a directory containing the string 'ShieldBreak'. This could indicate an attempt to utilize or manipulate WER for debugging or anti-forensic activities in non-standard locations.
This rule monitors for potential privilege escalation or process manipulation by identifying non-system processes that interact with or follow execution patterns associated with MsMpEng.exe (Microsoft Defender) within a short timeframe. It specifically looks for a lower-privileged process triggering an activity related to the Defender service, followed immediately by a system-privileged process on the same device, which may indicate a bypass or injection technique used to gain or abuse system permissions.
Detects instances where cmd.exe is executed within the context of the 'NT AUTHORITY\SYSTEM' account, but the parent process was not initiated by a SYSTEM account. This behavior is often indicative of privilege escalation where an adversary leverages a service or process to execute commands with elevated privileges.
Detects the creation of a shortcut file named 'SystemIn.lnk' using PowerShell, a technique associated with the QUICSILVER malware to establish persistence. The rule monitors for PowerShell command-line arguments involving 'WScript.Shell' and 'CreateShortcut' alongside the specific file name.
Detects the execution of pythonw.exe, which is used as a host process for the SynkLoader RAT, initiating outbound network connections to identified adversary-controlled C2 domains. This behavior is indicative of an established command-and-control channel for command retrieval and data exfiltration.
Detects a malicious DLL component associated with SynkLoader, identified by specific exported functions (RunPowerShell, ExecutePowerShellCommand) and assembly metadata that facilitate executing PowerShell commands directly in memory.
Detects the creation or modification of registry keys under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. These keys are commonly used by adversaries to achieve persistence by ensuring arbitrary programs or scripts execute automatically when the current user logs in.
Page 448 of 1870








