Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution of LOLBins (PowerShell, mshta, cmd, wscript) directly spawned from common web browsers (explorer, chrome, edge, firefox) with command-line arguments indicative of malicious activity, such as base64-encoded commands, hidden window styles, or remote script download and execution.
This rule extracts and audits inventory information from local agents, including vendor, device name, account context, and associated process information. It is designed to provide visibility into the state and configuration of installed local agents within the environment.
Detects the addition of new domain accounts using the 'net group /add /domain' command. This activity can be indicative of an adversary establishing persistence or escalating privileges within a domain environment.
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
This rule monitors for successful GlobalProtect gateway connections from users who have not successfully connected in the preceding 30 days, specifically identifying users connecting with a client fingerprint of 'Microsoft Windows 10 Pro 64-bit'. This behavior is indicative of potential initial access using compromised or new credentials, or specifically flagging suspicious activity patterns associated with specific exploit proof-of-concept client fingerprints.
Detects high-frequency state changes in authentication events for a single account within a short time window. This type of 'flapping' behavior, where an account repeatedly toggles between different authentication statuses (e.g., success and failure) on one or more hosts, can be an indicator of brute force attempts, credential stuffing, or misconfigured automated authentication services.
This rule monitors process execution events and correlates them against a watchlist of known malicious or suspicious binary names, such as crypto-miners, unauthorized remote access tools, or renamed system utilities (LOLBins) being executed from suspicious locations.
This rule detects potentially unauthorized command-line activity originating from Power Platform-related execution environments (such as Copilot Studio or Power Platform sandboxes). It specifically monitors for the execution of common system administration binaries like cmd, powershell, or curl, which, when triggered from within a low-code/cloud runtime environment, may indicate a sandbox escape or an attempt to interact with the underlying host operating system.
This rule detects potentially malicious attempts to modify Windows process protection levels, often used by attackers employing Bring Your Own Vulnerable Driver (BYOVD) techniques. It identifies when processes use command-line arguments like 'PsProtectedSignerAntimalware' or 'SetProcessMitigationPolicy' to assign elevated protection levels, while simultaneously ensuring the initiating process is either unsigned or not a standard executable file, which is highly indicative of suspicious activity.
This rule detects sequences of suspicious process activity where multiple known LOLBins (Living Off the Land Binaries) execute in a chain. Specifically, it monitors for scenarios where a process from a predefined list (e.g., msdt.exe, mmc.exe, rundll32.exe) initiates another process from the same list, often indicative of proxy execution or privilege escalation techniques involving suspicious command-line parameters like '-embedding', 'NtLoadDriver', or '/i:'.
This rule monitors process execution events and correlates them against a watchlist of known malicious or suspicious binary names, such as crypto-miners, unauthorized remote access tools, or renamed system utilities (LOLBins) being executed from suspicious locations.
This rule detects suspicious execution patterns of addinutil.exe, a legitimate .NET utility that can be abused for arbitrary code execution. It specifically looks for two conditions: 1) addinutil.exe being executed from its standard .NET Framework directories with the '-AddinRoot .' argument, which is a known LOLBAS technique to load a payload from the current directory, and 2) addinutil.exe being executed from an uncommon or non-standard directory, which could indicate an adversary has copied the utility to a different location for malicious purposes.
Detects suspicious command-line activity originating from TeamCity service processes on Windows. The rule looks for unexpected child processes (e.g., cmd.exe, powershell.exe, curl.exe) initiated by the TeamCity server or associated Java processes, which may indicate exploitation of an unauthenticated remote code execution vulnerability.
Detects bulk file copy to staging directories, mass file read access, mailbox-export-rule creation, and bulk PST/mailbox access, excluding DLP/eDiscovery/legal-hold exports tagged with a case ID and scheduled data-migration windows.
Detects OpenSSH installation on Windows hosts, unexpected internal SSH sessions, and SSH tunnels terminating at an external (non-RFC1918) destination — particularly from SSL-VPN admin hosts — excluding documented DevOps CI/CD runners and known bastion hosts.
A GitHub maintainer account related to the keyv/cacheable npm package ecosystem was compromised. The attacker published malicious versions of these packages, which affected more than 400 npm packages. The malware is designed to steal cloud credentials, developer secrets, CI/CD secrets, AI tool configuration files, and cryptocurrency wallet data. It also creates persistence using Claude Code hooks and VS Code tasks.json files, and sends stolen data to attacker-controlled GitHub repositories and C2 domains.
Reference article: https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
Reference article: https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
Detects execution of whoami.exe as NT AUTHORITY\SYSTEM within a short window of, and parented by, a suspicious SYSTEM-privileged shell spawn — a common post-exploitation confirmation step following successful ShieldBreak exploitation. Standalone whoami execution is excluded by design.
This rule detects the execution of known Remote Monitoring and Management (RMM) or remote access tools on devices where they have not been observed within the previous 90-day baseline (excluding the most recent 7 days). This pattern is often indicative of an adversary introducing unauthorized remote access capabilities for persistence or lateral movement.
KQL Query
Detects potential data exfiltration attempts using PowerShell by identifying Invoke-WebRequest usage with specific flags (Put, ContentType, InFile) or encoding patterns (EncodedCommand) while targeting sensitive file extensions, directories, or suspicious network destinations.
Detects the full technical staging sequence unique to the ShieldBreak CLFS time-of-check-to-time-of-use (TOCTOU) technique: cloud provider registration, WD_TARGET/WD_SHADOW object-manager directory creation, WD_SCAN object-link creation under the normal and CLFS namespaces, ntdll.dll copy into a BERLIN alternate data stream, the link-deletion/CLFS-log-lock race sequence, and the final phoneinfo.dll:stream lock confirming the file-overwrite primitive succeeded.
Page 473 of 1866






