Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,173 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,961
Categories
17,726
9,432
3,736
3,667
3,657
Platforms
39,173
6,877
6,386
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects registration of an unrecognized cloud sync provider combined with placeholder file creation within a short window, consistent with ShieldBreak's TOCTOU race staging technique. Excludes signed installs/re-registrations of known legitimate cloud sync clients (OneDrive, Dropbox, Google Drive, Box).
Detects CoolClient process injection into a suspended synchost.exe instance via remote thread creation and thread-context redirection.
The following analytic detects the creation of screen capture files by the Braodo stealer malware. This stealer is known to capture screenshots of the victim's desktop as part of its data theft activities. The detection focuses on identifying unusual screen capture activity, especially when images are saved in directories often used by malware, such as temporary or hidden folders. Monitoring for these files helps to quickly identify malicious screen capture attempts, allowing security teams to respond and mitigate potential information exposure before sensitive data is compromised.
This rule detects potential SQL injection attacks and anomalous request patterns targeting the '/api/session/reset_password' IIS API endpoint. It identifies common SQL injection payloads within the HTTP request body and flags excessive requests to this endpoint that lack expected JSON structure, which may indicate automated scanning or credential stuffing attempts.
This rule detects large file uploads (greater than 100MB) from endpoints to unmanaged or personal cloud storage services such as Google Drive, OneDrive, and Dropbox. This behavior may indicate unauthorized data exfiltration or the improper use of unapproved cloud storage platforms to move sensitive data outside of corporate control.
Detects potential DeadLock ransomware activity by correlating a high volume of file renames (using the .dlock extension) within a short window, alongside the creation of known ransomware notes (HOW_RECOVER*.txt or RECOVERY_CHAT*.html) or the modification of the desktop wallpaper registry key to point to a file in C:\ProgramData.
Detects a credential-phishing email linking to a spoofed Microsoft device-code login flow (deviceaddcredential.srf) from a sender/recipient domain mismatch, or delivery of the associated known malicious attachment hash.
Detects the execution of LOLBins (PowerShell, mshta, cmd, wscript) directly spawned from common web browsers (explorer, chrome, edge, firefox) with command-line arguments indicative of malicious activity, such as base64-encoded commands, hidden window styles, or remote script download and execution.
This rule detects PowerShell processes (powershell.exe, powershell_ise.exe, pwsh.exe) that execute the 'Compress-Archive' cmdlet in conjunction with strings indicative of data staging or exfiltration workflows (e.g., 'ZIPDOWNLOAD', '-DestinationPath'). The detection logic further narrows the scope by identifying if the parent process (InitiatingProcessCommandLine) involved activities related to downloading or uploading files, suggesting an automated staging and potential exfiltration sequence often seen in malicious backdoors.
The following analytic detects modification of the PYTHONPATH environment variable in conjunction with a package installation process.
Python looks up the `sys.path` variable, which is generated by combining user and site folders with `.pth` files and the value of the PYTHONPATH environment variable, to determine which directories to use for importing modules.
If an adversary is able to control the value of PYTHONPATH, they can point it to an attacker-controlled directory and hijack imported packages, achieving user-level persistence across future Python invocations and new shell sessions.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked by the affected user.
Python looks up the `sys.path` variable, which is generated by combining user and site folders with `.pth` files and the value of the PYTHONPATH environment variable, to determine which directories to use for importing modules.
If an adversary is able to control the value of PYTHONPATH, they can point it to an attacker-controlled directory and hijack imported packages, achieving user-level persistence across future Python invocations and new shell sessions.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked by the affected user.
KQL Query
Detects command-line execution patterns involving the instantiation of potentially malicious COM objects (such as ADODB.Stream, Shell.Application, or network-related objects) using WScript.CreateObject or ActiveXObject. This pattern is commonly used in malicious JScript/VBScript to facilitate file operations, command execution, or network communication.
This rule detects mass disabling of Windows Event Log channels by monitoring registry value modifications where multiple 'Enabled' values are set to '0' within a short timeframe. This behavior is indicative of anti-forensics activity where an adversary attempts to suppress specific log sources to evade detection.
Detects a Zoom client (zoom.exe/CptHost.exe) crashing or spawning an unexpected non-Zoom child process with an access-violation/stack-corruption/heap-overflow signature within 10 seconds of annotation-channel network activity, indicating attempted or successful exploitation of the ZOOMSDAY zero-click annotation RCE (CVE-2026-53413). Excludes known Zoom updater, crash-reporter, and screen-share helper processes.
Detects access-token duplication combined with CreateProcessAsUserA spawning the non-standard synchost.exe process outside System32 under a target interactive session.
Detects Microsoft Defender exclusions added via wmic/MSFT_MpPreference for a fake Windows Defender installation directory used to shelter CoolClient components.
This rule detects potentially malicious command execution (RCE) originating from AI orchestration platforms and development runtimes (such as Ollama, LangChain, AutoGen, CrewAI, n8n, Node.js, and Python). It flags instances where these processes spawn command shells (cmd.exe, powershell.exe, bash, sh) and execute suspicious command-line patterns indicative of code injection or command execution (e.g., eval(), exec(), subprocess, child_process). The rule uses a threshold of 3 or more occurrences in a 15-minute window per device and process to reduce noise.
Detects execution of processes that reference suspicious Windows API functions related to token manipulation or process injection, specifically when initiated by critical system processes like svchost.exe or lsass.exe. This activity often indicates attempts at credential access or privilege escalation.
Static file-based detection of the ACRStealer dropper, encrypted AutoIt payload, and DCRCVDrv.sys BYOVD driver via filenames, service/device names, signer names, and certificate serial. Certificate/signer matches only fire in combination with the driver file or service artifacts to avoid flagging the legitimate vendor certificate alone.
This rule detects the creation of potentially malicious web-accessible files (e.g., .aspx, .ashx, .asmx) within sensitive SharePoint directory paths by the w3wp.exe process. This behavior is indicative of a webshell upload, which is a common persistence mechanism used by adversaries after gaining access to a web server.
Detects HTTP POST requests characteristic of the Kynx Stealer's ChunkSender module. The rule monitors for specific URI patterns used during the exfiltration phase, where stolen data categories like passwords, cookies, and system information are sent to a remote C2 panel.
Page 466 of 1866






