Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects HTTP traffic identified as Sauron Loader, characterized by specific POST requests to hardcoded domains, URI path structures, and user-agent strings indicative of automated C2 activity.
Detects HTTP traffic identified as Sauron Loader, characterized by specific POST requests to hardcoded domains, URI path structures, and user-agent strings indicative of automated C2 activity.
Detects instances where attrib.exe is executed with minimal or no command-line arguments, launched by processes other than standard Windows shell processes like cmd.exe, explorer.exe, or powershell.exe. This pattern is often indicative of potential masquerading, where malicious binaries are renamed to mimic legitimate Windows system utilities to evade detection.
Detects instances where the rnpkeys.exe process initiates a network connection shortly after its execution. The RNP (OpenPGP) utility is generally used for local cryptographic operations; unexpected network activity from this process may indicate potential misuse, data exfiltration, or malicious use of the tool for command-and-control communication.
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
Detects instances where the process rnpkeys.exe loads suspicious DLLs (rnp.dll or tdwp.dll) without subsequent network activity within a 120-second window. This behavior is indicative of potential DLL side-loading where the process is used to execute malicious payloads without establishing communication.
This rule detects potentially malicious C2 communication by monitoring high-frequency HTTP POST requests from the 'rnpkeys.exe' process. It aggregates network events over 30-second windows and flags activity exceeding a threshold of 5 POST requests directed at known suspicious domains or specific high-port network destinations, which is characteristic of beaconing or data exfiltration activity.
Detects the execution of known NTLM relay and coercion tools (such as PetitPotam, EfsPotato, PrinterBug, DFSCoerce, or Coercer) when attempting to coerce a local authentication or credential relay using the local loopback address. These tools leverage various RPC-based techniques to force the local machine to authenticate to an attacker-controlled source, facilitating NTLM relay attacks.
Detects the presence or execution of artifacts associated with the TrustSink proof-of-concept (deploy.py, cleanup_eam.py, deploy_state.json), which is used to register or remove rogue Entra authentication providers.
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
Detects the creation of a Windows scheduled task where the task name contains the string 'keyroll', often associated with credential rotation or suspicious persistence mechanisms.
Detects the execution of attrib.exe spawned by known Sauron Loader process names (rnpkeys.exe, rnp.exe, or tdwp.exe). The rule flags instances where attrib.exe is executed without its typical command-line arguments (file attribute flags), suggesting it is being used as a surrogate process for injected C2-tasked shellcode.
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
Detects network communication associated with the Rapuncel MaaS (Malware-as-a-Service) campaign, specifically identifying the Command and Control (C2) connection, GitHub Pages-based redirect chains, and subsequent delivery of large, suspicious ZIP archives containing renamed executable/system files.
Detects the execution of known Python scripts (CES_Enroll.py, ntlm_ces_relay.py, ces_negotiate_ntlm.py) often associated with NTLM relay attacks or forced authentication techniques. These scripts leverage Python to interact with authentication protocols or relay requests.
Page 61 of 1866


