Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution of potentially malicious processes originating from common mail client attachment cache directories, the use of suspicious double extensions in file names, or common command-line interpreters being spawned by Microsoft Office applications, which are high-confidence indicators of phishing or malicious document exploitation.
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
Detects the deployment and activity of the MeshCentral remote management agent (meshagent), including process execution, service creation, and network communication to MeshCentral infrastructure. This behavior is indicative of unauthorized persistence and remote command-and-control, often associated with post-compromise activity such as that observed by ShinyHunters.
Detects web requests targeting Oracle PeopleSoft Integration Broker (PSIGW) endpoints that contain suspicious query parameters associated with exploitation attempts, such as path traversal sequences, command injection patterns, or Java-based class invocations. This rule is designed to identify exploitation attempts against PeopleSoft systems as observed in the mid-2026 ShinyHunters zero-day campaign.
Detects the installation or first execution of common remote monitoring and management (RMM) software, specifically AnyDesk, TeamViewer, or ScreenConnect, shortly after an identity change or MFA reset event, indicative of social engineering vishing-to-remote-access techniques often employed by threat actors such as Scattered Spider (UNC3944).
Detects potential NTLM relay attacks targeting Active Directory Certificate Services (AD CS) web enrollment endpoints, including subsequent certificate requests for sensitive templates. This pattern identifies attackers attempting to relay NTLM authentication to AD CS and potentially requesting certificates for high-privilege templates (e.g., DomainController, SubCA, Machine, or User) to facilitate privilege escalation.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Detects anomalous or potentially malicious LDAP queries on Domain Controllers, utilizing Event ID 1644 to monitor query filters. The rule identifies patterns commonly associated with reconnaissance and enumeration activities, including Kerberoasting (SPN enumeration), AS-REP roasting, delegation abuse, Active Directory Certificate Services (AD CS) enumeration, BloodHound collection, and bulk user, group, or computer discovery.
Page 51 of 1870



