Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution of Nova ransomware (formerly RALord) by monitoring for its specific modular command-line interface arguments, which include file encryption commands, ransom note deployment, and specific ransom note filenames. The rule monitors process creation events for strings like 'encrypt-all', 'encrypt-path', 'readme-add', '--workers', and the presence of the 'README_NOVA.me' ransom note or unique file extensions associated with its encryption activity.
Detects execution of 'rnpkeys.exe' and associated DLLs ('rnp.dll' or 'tdwp.dll') located within the '\ProgramData\keyroll\' directory, which is a common persistence or staging location for malicious activity.
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
Detects the execution of known Python scripts (CES_Enroll.py, ntlm_ces_relay.py, ces_negotiate_ntlm.py) often associated with NTLM relay attacks or forced authentication techniques. These scripts leverage Python to interact with authentication protocols or relay requests.
Detects credential-stuffing campaigns that employ AI/ML-tuned inter-request timing jitter to bypass traditional rate-limiting and fixed-interval bot detection, specifically flagging interactive or network logon failures on Windows hosts.
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
This rule detects processes command lines containing specific strings ('EmbedHtml', 'EmbedHtml::GetUrl', 'GetUrl()') associated with suspicious NSIS (Nullsoft Scriptable Install System) script behavior often linked to the OpenSUpdater malware downloader, which uses these calls to fetch additional malicious payloads.
This rule detects a single device making a high volume of connections to known machine learning model and dataset hosting repositories (e.g., Hugging Face, Kaggle, TensorFlow) within a short timeframe. Such activity may indicate bulk exfiltration of sensitive internal research data, proprietary models, or large datasets.
This rule detects the creation or presence of specific file artifacts ('PDF_C2089_20260911100446.exe' and 'active_desktop_render_x64.dll') within the '\AppData\Microsoft\Update\' directory. These file names and paths are characteristic of potential malware staging or persistence mechanisms, specifically associated with the SilverFox threat activity.
This rule detects the presence of command line artifacts, filenames, and strings associated with the SilverFox malware. These strings indicate the execution of a malicious desktop monitoring component ('active_desktop_launcher.exe') or the use of specific IPC/configuration markers ('@@RAPID_CFG_START@@') characteristic of this threat's tradecraft.
This rule detects executable files (ending in .exe) executing from a specific subdirectory within the user's AppData path (\AppData\Microsoft\Update\). This path is often used by adversaries to masquerade malicious activity or persistence mechanisms as legitimate update processes. The rule excludes common system service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise, focusing on processes initiated by user-level accounts.
Detects the specific pattern associated with Storm-2570 for enabling Remote Desktop Protocol (RDP) on a target host to facilitate lateral movement. The detection looks for registry modifications to disable RDP denial (fDenyTSConnections=0), firewall rules allowing TCP port 3389 via netsh or PowerShell, and the deployment of these configurations using PsExec against a target host list file.
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
Page 54 of 1870


