Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects anomalous, non-browser process activity interacting with Microsoft Teams APIs associated with the TWINLOOT threat campaign. The rules identify suspicious token retrieval requests and unauthorized authentication headers from processes that do not identify as legitimate browser or Teams application agents, indicating potential abuse of application access tokens and authentication flows.
The following analytic detects a Windows Defender malware detection or remediation event where the scanned path resolves through the NT object manager namespace (\globalroot\).
It leverages Windows Defender Operational log EventCodes 1116 and 1117 to identify this activity.
In the ShieldBreak exploit, this is how Defender is coerced into hydrating a cloud file placeholder and copying attacker content through a symbolic link chain that ultimately writes into C:\Windows\System32.
If confirmed malicious, this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
It leverages Windows Defender Operational log EventCodes 1116 and 1117 to identify this activity.
In the ShieldBreak exploit, this is how Defender is coerced into hydrating a cloud file placeholder and copying attacker content through a symbolic link chain that ultimately writes into C:\Windows\System32.
If confirmed malicious, this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
Detects registry modification/deletion attempts blocked with STATUS_ACCESS_DENIED on hosts running msagent.sys, restricted to msagent/RNG-related key paths.
Detects execution of the typosquatted process synchost.exe (distinct from the legitimate svchost.exe) when unsigned or running outside System32.
This rule detects potential webshell activity by monitoring the correlation between web server processes spawning suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe) and the creation of executable or script files within identified web directories. The logic establishes a high-confidence correlation when both events occur on the same device within a 15-minute window, while also surfacing uncorrelated individual process spawns or suspicious file writes as lower-confidence indicators. It includes exclusions for known administrative and deployment processes to reduce noise.
Detects SilentDataCollector host-based surveillance: recurring screenshot capture, keylogging, WhatsApp Web automation, or known stealer binary execution.
This rule detects potentially unauthorized command-line activity originating from Power Platform-related execution environments (such as Copilot Studio or Power Platform sandboxes). It specifically monitors for the execution of common system administration binaries like cmd, powershell, or curl, which, when triggered from within a low-code/cloud runtime environment, may indicate a sandbox escape or an attempt to interact with the underlying host operating system.
Detects instances where AI coding assistants (e.g., Cursor, Claude, Copilot) are observed interacting with specific configuration or sensitive files and subsequently initiating suspicious shell commands. The rule correlates file read activity (containing keywords like 'skill', 'preflight', '.ssh', or '.aws') followed closely by execution of potentially malicious commands like 'whoami /priv', credential decoding, or registry exploration, indicating potential abuse of the assistant's context.
Detects high-risk or uncategorized events involving the 'Isolate' action or Remote Browser Isolation (RBI) as logged by Microsoft Defender for Endpoint.
Detects anomalous, frequent, or repetitive device crash events (including BSODs) on a single device, which may indicate system instability, hardware failure, or an attempt to induce a Denial of Service (DoS) condition on the endpoint.
Detects devices exhibiting sustained high CPU or memory utilization (>= 90%) for a duration of at least 30 minutes, which may indicate resource exhaustion, performance degradation, or potentially malicious activity such as cryptocurrency mining, denial-of-service, or other unauthorized resource-intensive processes.
Detects BumbleBee loader binaries that utilize the GetSystemDefaultLocaleName API to perform geofencing, intentionally exiting if the system locale matches specific CIS (Commonwealth of Independent States) region strings. This behavior is used by the malware to avoid infection of systems in these regions.
This rule detects the suspicious execution of the psql.exe command-line client interacting with the Veeam Backup database. It specifically monitors for attempts to query database tables containing sensitive user_name and password information, often correlated with WMI or encoded PowerShell execution, which suggests an attempt to extract credentials from backup software.
Detects high-risk or uncategorized events involving the 'Isolate' action or Remote Browser Isolation (RBI) as logged by Microsoft Defender for Endpoint.
Detects command-line activity indicative of attempts to disable, bypass, uninstall, or interfere with the Netskope security agent functionality on an endpoint.
Suricata signature chain detecting a burst of 20+ 592-byte ExtChild AddObj annotation messages from a single source within 5 seconds (heap-spray pattern), followed by a RemoveObj/ModifyObj teardown operation consistent with dispatch through a corrupted vtable pointer — the full CVE-2026-53414 heap overflow and control-flow hijack chain.
Suricata signature for a Zoom annotation PDU carrying opcode 0x10001 (AddObj) delivered on the downstream acknowledgement channel (which should only carry 0x10002/AddObjAck), indicating sender-role/opcode confusion that lets any participant forge presenter-privileged annotation objects (ZOOMSDAY, CVE-2026-53413/53414/53415).
Correlates end-to-end encryption (E2EE) enablement events with either an absence of expected server-side annotation-filter log entries or a malformed annotation payload indicator (CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange/CAnnoExtBlock/CAnnoPduAddObj fields) within the same 15-minute window, surfacing meetings where Zoom's server-side ZOOMSDAY mitigation could not inspect traffic.
Detects a Zoom client (zoom.exe/zoom.us/CptHost.exe) terminating abnormally (SIGABRT/SIGSEGV/stack corruption) from within the annotation module (libannotate.so) within 30 seconds of receiving a message-type-75 (CAnnoObjAutoMetaShape) annotation object, indicating exploitation of the linked-list unlink write-what-where primitive (CVE-2026-53415). Excludes update-triggered restarts and graceful shutdowns.
Detects presence of the EICAR AV test file only when co-occurring with ShieldBreak exploit artifacts (PoC binary, build files, or Warden.dll) in the same directory or process context, indicating exploit development/testing activity rather than routine AV testing.
Detects network access to known repositories hosting the publicly disclosed ShieldBreak Microsoft Defender zero-day bypass PoC/tooling (GitHub, Project Nightcrawler, Church of Malware mirrors) via HTTP host/URI or TLS SNI matching.
Page 468 of 1866




