Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects JWR phishing kit's fake loading progress-bar overlay (p-bar/_pbar with a maximal z-index) used to mask the hidden iframe's C2 negotiation while building victim trust.
Detects the JWR phishing kit's JwrControlInstruction mechanism relaying operator commands to the victim browser across branded login, OTP/2FA capture, and card-retry page flows.
Detects the execution of Python or Pythonw processes with command-line arguments that include base64 decoding followed by the exec() function. This pattern is commonly used by adversaries to execute obfuscated or encoded malicious code directly in memory to evade detection.
Detects installation or execution of AnyDesk, Google Remote Desktop, or MobaXterm from user-writable directories (Downloads, Temp, AppData) outside the approved software baseline, excluding code-signed installs pushed via Intune/SCCM.
Potential exploitation of JetBrains TeamCity (Unauthenticated RCE, CVE-2026-63077) looking for suspicious child processes spawned by TeamCity services.
This rule detects sequences of suspicious process activity where multiple known LOLBins (Living Off the Land Binaries) execute in a chain. Specifically, it monitors for scenarios where a process from a predefined list (e.g., msdt.exe, mmc.exe, rundll32.exe) initiates another process from the same list, often indicative of proxy execution or privilege escalation techniques involving suspicious command-line parameters like '-embedding', 'NtLoadDriver', or '/i:'.
Detects PlugX-style initial-foothold staging: process injection followed within minutes by a dropped file that is then executed, excluding known-benign AV/EDR/updater injectors and targets.
Detects msagent.sys driver load correlated with subsequent protection (reduced handle access rights) of an unsigned, non-standard synchost.exe process within a 1-hour window.
Detects DKOM-style kernel process hiding: processes created but never appearing in periodic enumeration snapshots across multiple consecutive polls.
This rule detects the use of double extensions in file names to masquerade executable files as benign document or media file types (e.g., 'document.pdf.exe'). This is a common technique used by attackers to trick users into executing malicious files by hiding their true extension.
Detects the msagent.sys signed kernel-mode rootkit driver used by the CoolClient backdoor (HoneyMyte/Mustang Panda)
Detects network retrieval of the ShieldBreak exploit PoC or the UnDefend companion tool from their known distribution infrastructure (git.projectnightcrawler.dev, github.com/Nightmare-Eclipse/UnDefend) via TLS SNI or HTTP host/URI matching.
This analytic detects uncommon processes reading or requesting read access to sensitive files from cloud providers on Windows endpoints.
It monitors Windows Security Event 4663 for ReadData (AccessMask 0x1) operations against sensitive files from cloud providers such as Azure.
Access by any process outside the known toolchain may indicate credential theft or cloud identity reconnaissance activity, including infostealer behavior such as one observed in Vidar Stealer variants.
This detection currently only supports Azure sensitive files, but will be extended to support other cloud providers in the future.
It monitors Windows Security Event 4663 for ReadData (AccessMask 0x1) operations against sensitive files from cloud providers such as Azure.
Access by any process outside the known toolchain may indicate credential theft or cloud identity reconnaissance activity, including infostealer behavior such as one observed in Vidar Stealer variants.
This detection currently only supports Azure sensitive files, but will be extended to support other cloud providers in the future.
The following analytic detects suspicious remote thread execution in processes such as Taskmgr.exe, calc.exe, and notepad.exe, which may indicate process injection by malware like Qakbot. This detection leverages Sysmon EventCode 8 to identify remote thread creation in specific target processes. This activity is significant as it often signifies an attempt by malware to inject malicious code into legitimate processes, potentially leading to unauthorized code execution. If confirmed malicious, this could allow attackers to execute arbitrary code, escalate privileges, or maintain persistence on the compromised host.
The following analytic detects an access request on the uninstall registry key. It leverages Windows Security Event logs, specifically event code 4663. This activity is significant because adversaries or malware can exploit this key to gather information about installed applications, aiding in further attacks. If confirmed malicious, this behavior could allow attackers to map out installed software, potentially identifying vulnerabilities or software to exploit, leading to further system compromise.
This rule detects modifications to BitLocker registry keys associated with encryption settings, such as enabling/disabling device encryption or modifying startup requirements. These actions could be used by an adversary to weaken, bypass, or disable full-disk encryption to facilitate data theft or gain persistent access.
This rule detects high volumes of network traffic originating from processes other than common web browsers (chrome, msedge, firefox) to specific edge computing and logging infrastructure (ingest.sentry.io, workers.dev, pages.dev). This behavior is indicative of non-browser processes, potentially malicious implants or scripts, using legitimate cloud-based edge services as command-and-control (C2) infrastructure or for data exfiltration.
This rule identifies network connections using deprecated, insecure TLS versions (TLS 1.0, 1.1) or weak cipher suites (RC4, 3DES, NULL). The use of these legacy cryptographic protocols is a security risk, as they are vulnerable to various attacks like man-in-the-middle, and may indicate misconfigured servers, legacy infrastructure, or attempts by an adversary to downgrade encryption to facilitate traffic interception or inspection.
Detects DLL sideloading of a malicious, AES-256-encrypted borlndmm.dll masquerading as an NVIDIA graphics library, loaded via the legitimate ACCA Software S.p.A.-signed ABRSubProcess.exe to launch OnyxC2.
This rule detects attempts to disable, stop, or uninstall various security products, including antivirus and EDR solutions, by monitoring command-line activity for administrative utilities like sc.exe, net.exe, wmic.exe, and PowerShell.
Detects DLL side-loading of the unsigned tbbmalloc.dll by the signed binary pgocvt.exe from the C:\ProgramData\TIEmounter\ staging directory — a second-stage follow-on payload technique in the ACRStealer campaign.
Page 469 of 1866



