Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potentially malicious command execution (RCE) originating from AI orchestration platforms and development runtimes (such as Ollama, LangChain, AutoGen, CrewAI, n8n, Node.js, and Python). It flags instances where these processes spawn command shells (cmd.exe, powershell.exe, bash, sh) and execute suspicious command-line patterns indicative of code injection or command execution (e.g., eval(), exec(), subprocess, child_process). The rule uses a threshold of 3 or more occurrences in a 15-minute window per device and process to reduce noise.
Detects execution of processes that reference suspicious Windows API functions related to token manipulation or process injection, specifically when initiated by critical system processes like svchost.exe or lsass.exe. This activity often indicates attempts at credential access or privilege escalation.
Static file-based detection of the ACRStealer dropper, encrypted AutoIt payload, and DCRCVDrv.sys BYOVD driver via filenames, service/device names, signer names, and certificate serial. Certificate/signer matches only fire in combination with the driver file or service artifacts to avoid flagging the legitimate vendor certificate alone.
This rule detects the creation of potentially malicious web-accessible files (e.g., .aspx, .ashx, .asmx) within sensitive SharePoint directory paths by the w3wp.exe process. This behavior is indicative of a webshell upload, which is a common persistence mechanism used by adversaries after gaining access to a web server.
Detects HTTP POST requests characteristic of the Kynx Stealer's ChunkSender module. The rule monitors for specific URI patterns used during the exfiltration phase, where stolen data categories like passwords, cookies, and system information are sent to a remote C2 panel.
Detects DCRCVDrv.sys driver used in ACRStealer BYOVD campaign via attacker-specific hashes, certificate serial, or atypical staging path; vendor metadata and PDB are supportive only
Detects a Windows Registry modification where the EnableLUA value under HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System is set to 0, which disables the User Account Control (UAC) feature. This modification weakens system security by disabling Admin Approval Mode for administrators.
Windows High-Value Account Disabled
Cortex XDR
Detects Windows Security Event ID 4725 which signals that a user account has been disabled. This rule specifically correlates the event with a locally maintained inventory of high-value accounts, such as executive, privileged, or service accounts, to identify potentially disruptive or unauthorized account access removal.
Detects the deletion of an Active Directory Group Policy Object (GPO) by monitoring Windows Security Event ID 5141 where the deleted object class is 'groupPolicyContainer'. This activity may indicate an attempt to weaken domain security controls or impair defenses.
Detects a DNS query for diagrtrack.com, a typosquat of Windows DiagTrack registered to serve as this backdoor's C2 infrastructure (dormant since early 2021).
Detects creation and locking of a CLFS log file matching the ShieldBreak-specific naming/path pattern, used to synchronize the exploit's TOCTOU race window against Microsoft Defender. Excludes legitimate CLFS consumers (MSMQ, TxR/TxF) and Windows servicing operations.
Detects presence of ShieldBreak exploit project source, resource, and build files (e.g. ShieldBreak.cpp, ShieldBreak.vcxproj, shlbrk.ico) using exact known project artifact names, indicating local exploit development or PoC compilation activity.
Detects the creation of new endpoint prevention policy rules for Windows, Linux, or macOS within the Cortex management audit logs. This activity allows security administrators to monitor changes to security posture and endpoint protection configurations.
Detects edits to existing Windows, Linux, or macOS endpoint prevention policy rules within Cortex management audit telemetry. These modifications can impact endpoint security posture, necessitating audit and verification to ensure changes were authorized and do not reduce security coverage.
Detects ntdll.dll being copied into an alternate data stream at a ShieldBreak-specific staging path, used to prepare the overwrite of a protected system DLL. Excludes legitimate backup, imaging, and EDR/forensic tooling that streams or duplicates system DLLs.
This rule detects the installation of a new VS Code extension occurring in close temporal proximity to network communication with the official VS Code marketplace or unpkg domains. This pattern is designed to surface potential supply chain compromises where malicious extensions may be deployed to developers' machines.
Detects Windows Defender process-level interaction consistent with the ShieldBreak exploit: MsMpEng.exe spawning an unexpected child process (excluding known-legitimate Defender helpers), or Defender's on-access scanner being triggered against unusual globalroot\BaseNamedObjects object-manager paths instead of normal filesystem paths.
Detects C2Looper v1 HTTP beaconing and result reporting to hardcoded C2 IP addresses over port 8888 via the /api/beacon and /api/result endpoints.
Detects the C2Looper secondary payload dropped as pld.exe under %LocalAppData%, typically staged as a ransomware precursor after backdoor check-in.
This rule Hunts Microsoft Defender for Endpoint DeviceFileEvents for .aspx/.ashx/.asmx files created by w3wp.exe (the IIS worker process) inside SharePoint-specific directories (wss\VirtualDirectories, Web Server Extensions, TEMPLATE\LAYOUTS, App_Code, App_Web, \bin\) — a classic webshell-drop pattern used once an attacker has already gained code execution on the server. It excludes benign SYSTEM/TrustedInstaller writes of default.aspx/upgrade.aspx to cut noise from normal patching/upgrade activity. This is a post-exploitation signature — it doesn't detect the exploit itself, only the artifact an attacker typically drops afterward.
CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort.
Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort.
Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
Detects module or image load events where the image lacks an associated on-disk path (FolderPath is empty). This behavior is indicative of in-memory code loading, such as reflective loading or the execution of Beacon Object Files (BOFs), where malicious code is mapped directly into process memory rather than loaded via the standard OS image loader.
Page 467 of 1866




