Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,173 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,961
Categories
17,726
9,432
3,736
3,667
3,657
Platforms
39,173
6,877
6,386
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects unauthorized modifications to the SAM registry hive (specifically keys and values related to user account RIDs) by non-system processes, which is a technique used in RID hijacking to grant elevated privileges or create hidden accounts.
Detects the 12KB RtkNGUI64.exe backdoor built without a C runtime, using GCC (tdm64-1) 4.9.2 and custom CRC/table-based string obfuscation
Detects a fake desktop.ini file combining a legitimate-looking ShellClassInfo/LocalizedResourceName lure (shell32.dll,-21781) with a C2 domain hidden as unary-encoded trailing whitespace after byte offset 174 -- consolidates the lure-content and whitespace-encoding indicators into one high-fidelity rule
Detects Cortex-managed endpoints that are currently in a disconnected state and are cross-referenced against an inventory of critical or sensitive assets. This rule highlights potential gaps in security monitoring and visibility for high-value systems.
Detects execution of RClone from non-standard directories or outbound transfer to cloud endpoints outside an approved destination list, consistent with Gunra's pre-encryption data-exfiltration tooling.
System File Execution Location Anomaly
Cortex XDR
Detects Windows system binaries and commonly abused native LOLBins executing from outside their expected system directories, indicating a renamed, relocated, or imposter copy consistent with masquerading, DLL side-loading staging, or process-name spoofing.
Detects Impacket-style (wmiexec, secretsdump, atexec, psexec.py, smbclient.py) and PsExec SMB admin-share lateral movement, excluding approved IT admin accounts and management servers.
Detects RDP-based lateral movement, including pivots into VDI, AD, and authentication infrastructure, excluding known bastion/jump hosts and flagging sessions from atypical source workstations or off-hours timing.
This rule detects the execution of 'cmd.exe' when it is spawned by a process that is not part of a common list of authorized parent processes. This behavior is often indicative of potential malicious activity, as adversaries may attempt to spawn shells from unexpected applications to maintain persistence, execute secondary payloads, or perform lateral movement.
Detects the creation and configuration of a Windows service named 'media_updaten' via command-line utilities (sc.exe) or direct registry modification. This service is associated with CoolClient for persistence to relaunch 'Sang.exe' with a 'work' parameter.
Detects remote process creation via wmic.exe/WmiPrvSE.exe and suspicious WMI event subscriptions, excluding known configuration-management platform service accounts (SCCM, Ansible, Puppet) and requiring the WMI connection to be the first-ever observed connection between the source/destination host pair.
Detects file creation, write, or rename operations to specific paths known to be used in exploitation of CVE-2026-63077.
This rule analyzes recent agent telemetry to identify and summarize the distribution of local agent vendors present in the environment over a 30-day lookback period. It extracts vendor information from agent metadata and provides a frequency count to assist in auditing deployed infrastructure agents.
Detects the ShieldBreak Defender-scan TOCTOU exploit locking an alternate data stream on the protected system DLL phoneinfo.dll immediately prior to an arbitrary write — the core privilege-escalation primitive of CVE-2026-50656. Excludes legitimate Windows Update/servicing operations.
This rule detects potentially malicious command execution (RCE) originating from AI orchestration platforms and development runtimes (such as Ollama, LangChain, AutoGen, CrewAI, n8n, Node.js, and Python). It flags instances where these processes spawn command shells (cmd.exe, powershell.exe, bash, sh) and execute suspicious command-line patterns indicative of code injection or command execution (e.g., eval(), exec(), subprocess, child_process). The rule uses a threshold of 3 or more occurrences in a 15-minute window per device and process to reduce noise.
This rule detects high volumes of network traffic originating from processes other than common web browsers (chrome, msedge, firefox) to specific edge computing and logging infrastructure (ingest.sentry.io, workers.dev, pages.dev). This behavior is indicative of non-browser processes, potentially malicious implants or scripts, using legitimate cloud-based edge services as command-and-control (C2) infrastructure or for data exfiltration.
This rule detects modifications to BitLocker registry keys associated with encryption settings, such as enabling/disabling device encryption or modifying startup requirements. These actions could be used by an adversary to weaken, bypass, or disable full-disk encryption to facilitate data theft or gain persistent access.
Detects command-line activity indicating an attempt to extract generic passwords from Google Chrome or Brave browser credential storage, often associated with tools that access the 'Safe Storage' or similar password databases.
Detects deletion of Volume Shadow Copies and backup catalogs (vssadmin, wbadmin, wmic shadowcopy, bcdedit) consistent with Gunra ransomware's pre-encryption recovery-inhibition behavior, requiring correlated multi-command deletion sequences to reduce noise from routine backup retention.
Detects OS credential dumping of the Active Directory NTDS.dit database via ntdsutil, VSS-based extraction, or Impacket's secretsdump.py, excluding approved AD backup jobs and accounts.
This rule detects potentially malicious activity leveraging the Windows Certutil utility for downloading, decoding, and executing files or payloads. It monitors process command line arguments to identify common download flags, hex/base64 decoding operations, evasion techniques, and interaction with high-risk file types or directories. The rule calculates a severity score based on the combination of these behaviors, such as downloading and decoding a file, or executing content from a temporary directory.
Page 470 of 1866







