Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects the execution of Python-based tunneling tools located in the 'C:\Users\Public\indigo\' directory, which is a known staging location for malicious implants used in covert tunneling operations.
Detects a suspicious Microsoft Teams MSI installer (msiexec.exe) spawning a PowerShell child process or referencing a known dead-drop resolver domain. This behavior is indicative of a trojanized installer used as an initial access vector to execute malicious payloads.
This rule detects known-malicious activity associated with Warlock ransomware and the ToolShell malware campaign (linked to Storm-2603). It monitors for process, file, and image-load events matching identified malicious file hashes, as well as network connection attempts to known malicious domains and URLs. It also includes monitoring for traffic to 'oastify.com', a domain commonly used for Burp Collaborator, which requires correlation with other indicators to confirm malicious intent.
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
The following analytic detects the execution of known remote access software within the environment. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and parent processes mapped to the Endpoint data model. We then compare with with a list of known remote access software shipped as a lookup file - remote_access_software. This activity is significant as adversaries often use remote access tools like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access. If confirmed malicious, this could allow attackers to control systems remotely, exfiltrate data, or deploy additional malware, posing a severe threat to the organization's security.
The following analytic identifies potential Kerberos ticket forging attacks, specifically the Diamond Ticket attack. This is detected when a user logs into a host and the GroupMembership field in event 4627 indicates a privileged group (e.g., Domain Admins), but the user does not actually belong to that group in the directory service. The detection leverages Windows Security Event Log 4627, which logs account logon events. The analytic cross-references the GroupMembership field from the event against a pre-populated lookup of actual group memberships. Its crucial to note that the accuracy and effectiveness of this detection heavily rely on the users diligence in populating and regularly updating this lookup table. Any discrepancies between the events GroupMembership and the lookup indicate potential ticket forging. Kerberos ticket forging, especially the Diamond Ticket attack, allows attackers to impersonate any user and potentially gain unauthorized access to resources. By forging a ticket that indicates membership in a privileged group, an attacker can bypass security controls and gain elevated privileges. Detecting such discrepancies in group memberships during logon events can be a strong indicator of this attack in progress, making it crucial for security teams to monitor and investigate. If validated as a true positive, this indicates that an attacker has successfully forged a Kerberos ticket and may have gained unauthorized access to critical resources, potentially with elevated privileges.
Detects the installation of remote management or connectivity tools (e.g., ScreenConnect, LogMeIn, PowerShell) using msiexec.exe with silent/quiet installation flags. This behavior is often associated with adversaries installing remote access software for persistent control after initial access.
Detects indicators associated with the ChatGPT Custom GPT ClickFix campaign across process, network connection, DNS, and HTTP telemetry: known malicious file hashes, C2 IP addresses, the chattypetty.com domain, and known payload-hosting URLs.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Detects a suspected ClickFix social engineering attack where a user is tricked into pasting malicious commands into Windows Terminal, leading to a PowerShell download, followed by the appearance of specific known malicious artifacts (LockScreenContentServer.exe, dui70.dll, or 1.bat) within 15 minutes on the same device.
This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
This rule detects unauthorized directory replication requests (DRSUAPI) using Active Directory Event ID 4662. It specifically monitors for access requests to sensitive directory replication object GUIDs (Get-Changes / Get-Changes-All) where the requesting user account is not a domain controller computer account. This behavior is a common indicator of DCSync credential dumping attacks performed by tools like Mimikatz or Impacket.
Detects instances where a PowerShell session is initiated from Windows Terminal (wt.exe) and subsequently executes a command to download an archive file (e.g., .zip) using common download cmdlets or methods. This pattern is often indicative of an attacker downloading and staging malicious payloads.
This rule detects potential DLL sideloading activity associated with the Lorem Ipsum Loader. It monitors image load events to identify specific legitimate Windows binaries (often used for sideloading) that load non-system DLLs. The rule filters out legitimate DLL loads from standard Windows system directories to highlight anomalous behavior.
Detects instances where a process that is not a recognized web browser (chrome, msedge, firefox, brave, opera, or explorer) accesses multiple unique browser cookie files. This is a common pattern for credential harvesting malware attempting to steal browser sessions.
Detects unauthorized access to sensitive browser credential and session data files (e.g., Login Data, Cookies, Local State, key4.db) by non-browser processes. This behavior is a common indicator of information-stealing malware attempting to extract saved credentials and session cookies to facilitate account takeover and bypass multi-factor authentication.
This rule detects unauthorized or suspicious modifications to Windows Defender exclusion registry keys. It monitors for registry key/value creation or set operations within Defender's exclusion paths for files or extensions. The rule evaluates the process responsible for the modification (e.g., expecting MsMpEng.exe for native keys or specific svchost.exe/gpsvc parameters for GPO keys) and flags modifications made by unauthorized processes or those involving suspicious, broad, or high-risk paths like C:\, C:\Temp, or User Public folders.
This rule monitors endpoint telemetry for indicators of compromise (IOCs) associated with known malicious activity. It checks for file creation, process execution, and network connections that match a defined list of malicious file hashes (SHA256, SHA1, MD5), C2 IP addresses, and malicious domains or URL patterns.
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
This rule detects successful network connections to known malicious IP addresses or the domain 'forgitlab.com', which are associated with the Azazel malware threat infrastructure.
Page 5 of 1866



