Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,173 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,961
Categories
17,726
9,432
3,736
3,667
3,657
Platforms
39,173
6,877
6,386
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the hard-coded RC4 key fragment used by BTR.sys to decrypt its transaction structure when co-located within 0x4000 bytes of the FEE1DEAD magic value and Version 2 header field, targeting the encrypted transaction/ADS payload content independent of driver binary version.
Detects suspicious Active Directory Replication Service (ADRS) requests originating from
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.
Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.
Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
Detects additions to privileged groups (e.g. Domain Admins) or modification of password-change-policy flags on a previously dormant account being reactivated, excluding changes linked to an approved change-management ticket and weighting more heavily for off-hours or non-standard admin workstation origin.
Detects creation of a scheduled task named 'IntelSoftwareUpdater' via schtasks.exe that launches pythonw.exe with run.pyw, used by the UNC5142 DeviceManager RAT for persistence, relaunching every 10 minutes.
Detects TLS sessions to Sapphire Sleet/UNC1069 Hostwinds C2 infrastructure presenting the exact self-signed certificate issuer string linked to the Mastra/axios campaigns.
This rule detects network communication attempts (connection success, request, or failure, or any traffic on port 443) targeting a specific malicious domain (notepadreleased.com) or IP address (85.158.110.78), while explicitly excluding common public DNS providers.
Detects a non-system process causing creation of CldFlt0.etl under C:\Windows\System32\LogFiles\CloudFiles\.
This path is initialised by the CldFlt driver when a process calls CfRegisterSyncRoot() or CfConnectSyncRoot().
In the RedSun exploit this is a side-effect of the DoCloudStuff() function that registers a fake sync provider to create the cloud-tagged bait file.
Legitimate cloud providers (OneDrive etc.) register sync roots from SYSTEM-level service processes, not from user-context executables.
This path is initialised by the CldFlt driver when a process calls CfRegisterSyncRoot() or CfConnectSyncRoot().
In the RedSun exploit this is a side-effect of the DoCloudStuff() function that registers a fake sync provider to create the cloud-tagged bait file.
Legitimate cloud providers (OneDrive etc.) register sync roots from SYSTEM-level service processes, not from user-context executables.
This rule detects potentially malicious attempts to modify Windows process protection levels, often used by attackers employing Bring Your Own Vulnerable Driver (BYOVD) techniques. It identifies when processes use command-line arguments like 'PsProtectedSignerAntimalware' or 'SetProcessMitigationPolicy' to assign elevated protection levels, while simultaneously ensuring the initiating process is either unsigned or not a standard executable file, which is highly indicative of suspicious activity.
This rule detects command-line activity that references sensitive Windows API functions or privileges associated with token manipulation and process privilege escalation, such as SeDebugPrivilege, SeImpersonatePrivilege, DuplicateTokenEx, CreateProcessWithTokenW, and NtSetInformationToken. The rule excludes common service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to focus on potentially unauthorized use by standard or administrative accounts.
This rule monitors for two critical firmware-related conditions: detected non-compliance with secure boot, UEFI, or TPM configuration standards via Microsoft Defender TVM, and explicit firmware or boot configuration change events reported by device telemetry. It is designed to identify potential tampering or misconfigurations that could facilitate bootkits or other pre-OS persistence mechanisms.
This rule identifies network connections using deprecated, insecure TLS versions (TLS 1.0, 1.1) or weak cipher suites (RC4, 3DES, NULL). The use of these legacy cryptographic protocols is a security risk, as they are vulnerable to various attacks like man-in-the-middle, and may indicate misconfigured servers, legacy infrastructure, or attempts by an adversary to downgrade encryption to facilitate traffic interception or inspection.
Detects the installation of a Manifest V3 browser extension that requests the 'chrome.proxy' permission as its sole permission. This behavior is indicative of potential malicious extensions designed to modify web traffic or route browser activity through an adversary-controlled proxy server.
This rule detects attempts to disable, stop, or uninstall various security products, including antivirus and EDR solutions, by monitoring command-line activity for administrative utilities like sc.exe, net.exe, wmic.exe, and PowerShell.
This rule detects scenarios where a new user account is created (Event ID 4720) and is subsequently logged into (Event ID 4624) within a 30-minute window. This behavior can indicate an adversary creating a backdoor or service account for persistence or lateral movement, followed by immediate usage of that account.
Detects execution of the SimpleChatProxy/'Chat Proxy' tool correlated with outbound traffic to an attacker-hosted image endpoint, used for operator-victim messaging and remote screenshot retrieval.
Detects an unsigned Loader.exe spawning a second unsigned executable that performs immediate outbound network fetch, matching the StopAndProtect loader/downloader chain with sandbox-evasion checks.
Detects the execution of LOLBins (PowerShell, mshta, cmd, wscript) directly spawned from common web browsers (explorer, chrome, edge, firefox) with command-line arguments indicative of malicious activity, such as base64-encoded commands, hidden window styles, or remote script download and execution.
This rule extracts and audits inventory information from local agents, including vendor, device name, account context, and associated process information. It is designed to provide visibility into the state and configuration of installed local agents within the environment.
Detects the addition of new domain accounts using the 'net group /add /domain' command. This activity can be indicative of an adversary establishing persistence or escalating privileges within a domain environment.
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
This rule monitors for successful GlobalProtect gateway connections from users who have not successfully connected in the preceding 30 days, specifically identifying users connecting with a client fingerprint of 'Microsoft Windows 10 Pro 64-bit'. This behavior is indicative of potential initial access using compromised or new credentials, or specifically flagging suspicious activity patterns associated with specific exploit proof-of-concept client fingerprints.
Page 472 of 1866





