Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects cmd.exe spawned by the Jewelbug native-messaging helper registered under the Microsoft-masquerading name com.microsoft.runedge, correlated with creation of the corresponding Chrome NativeMessagingHosts registry key — the mechanism the group uses to bridge its malicious 'PDF Viewer' browser extension to an interactive remote shell.
Detects potential exposure or use of cloud, source-control, and AI API credentials through sensitive files and process command lines.
Detects modifications to Active Directory objects of the class 'groupPolicyContainer' by monitoring Windows Security Event ID 5136. Unauthorized or unexpected GPO modifications can be used by attackers to weaken security controls, establish persistence, or facilitate privilege escalation across a domain.
Detects a 32-byte ICMP echo request carrying the backdoor's 8-byte bot ID, explicitly excluding the standard Windows ping.exe payload pattern (the dominant legitimate traffic at this size) and rate-limited to reduce alert volume.
Detects pass-the-hash and pass-the-ticket lateral authentication using NTLM/Kerberos-ticket reuse across multiple hosts without a corresponding interactive logon, excluding known NTLM-by-design service accounts.
This rule detects the use of the Windows Boot Configuration Data Editor (bcdedit.exe) to modify system recovery settings. Specifically, it looks for attempts to disable recovery features or instruct the boot manager to ignore failures. Such modifications are common in ransomware and destructive attacks to prevent users from using Windows recovery tools to restore the system or access backups.
This rule monitors DeviceEvents for the presence of the 'Runtime.addBinding' JavaScript interface within process creation or network inspection logs. This pattern is commonly associated with WebView-based applications exposing internal browser-side objects to the web content, which can potentially be exploited for remote code execution or cross-site scripting (XSS) if not implemented with strict security constraints.
Detects outbound network connections initiated by a process identifying itself as 'HeadlessChrome' within the User-Agent string. This behavior is indicative of a headless browser being misused as a proxy for Command and Control (C2) communication, as observed in msaRAT infections.
This rule monitors DeviceNetworkEvents for outbound connections to specific known malicious IP addresses (31.97.137.157 and 46.183.25.232) on port 45000, or connections to the domain 'bet.slotgambit.com'. These indicators are consistent with command and control (C2) activity.
KQL Query from file: Hunting Mirage kitten AKA unc1549
Detects the execution of the Bun JavaScript runtime by npm or node.js during lifecycle tasks (preinstall, postinstall, etc.). This behavior is highly indicative of the ChainDrop/Shai-Hulud supply chain worm, which uses npm lifecycle scripts to download and execute a second-stage payload using the Bun runtime.
User All Event Log Activity
Cortex XDR
This rule monitors Windows event logs for activity involving the SAM account name, which may indicate account enumeration, credential access attempts, or malicious modifications to account security settings.
Detects potential persistence mechanisms involving 'IBM SPSS WinWrap Basic IDE' or 'WinWrapIDE.exe'. The rule monitors for the creation of a scheduled task, registry run key additions, or event ID 4698 (scheduled task creation) associated with these artifacts. It further correlates these activities with suspicious account creation events (Event IDs 4720, 4732) on the same device within a one-hour window.
Detects two distinct offensive patterns: Impacket PsExec usage, identified by a Type-3 network logon followed within 2 minutes by an ADMIN$ service installation matching typical PsExec naming patterns; and DCSync replication requests originating from non-Domain Controller accounts.
Flags administrative, discovery, or reconnaissance-style actions occurring between 22:00-06:00 local time, suppressed during confirmed maintenance windows or valid on-call tickets, and requires co-occurrence with at least one other flagged detection before surfacing — a corroborating signal, not a standalone alert.
Detects anomalous OneDrive/SharePoint bulk download activity specifically correlated with execution of the named main.exe process, excluding Microsoft-signed sync clients and known enterprise migration tools (SharePoint Migration Tool, ShareGate).
This rule monitors for successful GlobalProtect gateway connections from users who have not successfully connected in the preceding 30 days, specifically identifying users connecting with a client fingerprint of 'Microsoft Windows 10 Pro 64-bit'. This behavior is indicative of potential initial access using compromised or new credentials, or specifically flagging suspicious activity patterns associated with specific exploit proof-of-concept client fingerprints.
This rule detects network communication attempts (connection success, request, or failure, or any traffic on port 443) targeting a specific malicious domain (notepadreleased.com) or IP address (85.158.110.78), while explicitly excluding common public DNS providers.
Detects LSASS memory access with credential-dumping-consistent access rights from unsigned or non-allowlisted processes, indicative of Mimikatz-driven credential theft used by Gunra ransomware affiliates.
Detects mass file rename/write events producing the distinctive .ENCRT extension used by Gunra's ChaCha20+RSA-4096 encryptor, scoped narrowly to avoid matching legitimate bulk file operations.
Detects modification of sensitive Active Directory LDAP attributes (msDS-AllowedToDelegateTo, msDS-AllowedToActOnBehalfOfOtherIdentity, scriptPath, msTSInitialProgram, msDS-KeyCredentialLink) via Windows Security EventCode 5136, and correlates the initiating session back to its originating logon (EventCode 4624) to surface the actor's SID, domain, source IP, and logon host. These attributes are commonly abused for Kerberos delegation abuse (constrained/resource-based constrained delegation), logon-script/Terminal-Services persistence, and Shadow Credentials (msDS-KeyCredentialLink) attacks. Includes anchor fields (initiator SID, domain controller, distinct-attribute count, operation correlation ID) to support precise, low-blast-radius tuning instead of broad exclusions.
Page 474 of 1866









