Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects instances where attrib.exe is executed with minimal or no command-line arguments, launched by processes other than standard Windows shell processes like cmd.exe, explorer.exe, or powershell.exe. This pattern is often indicative of potential masquerading, where malicious binaries are renamed to mimic legitimate Windows system utilities to evade detection.
Detects instances where the rnpkeys.exe process initiates a network connection shortly after its execution. The RNP (OpenPGP) utility is generally used for local cryptographic operations; unexpected network activity from this process may indicate potential misuse, data exfiltration, or malicious use of the tool for command-and-control communication.
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
Detects instances where the process rnpkeys.exe loads suspicious DLLs (rnp.dll or tdwp.dll) without subsequent network activity within a 120-second window. This behavior is indicative of potential DLL side-loading where the process is used to execute malicious payloads without establishing communication.
This rule detects potentially malicious C2 communication by monitoring high-frequency HTTP POST requests from the 'rnpkeys.exe' process. It aggregates network events over 30-second windows and flags activity exceeding a threshold of 5 POST requests directed at known suspicious domains or specific high-port network destinations, which is characteristic of beaconing or data exfiltration activity.
Detects the execution of known NTLM relay and coercion tools (such as PetitPotam, EfsPotato, PrinterBug, DFSCoerce, or Coercer) when attempting to coerce a local authentication or credential relay using the local loopback address. These tools leverage various RPC-based techniques to force the local machine to authenticate to an attacker-controlled source, facilitating NTLM relay attacks.
Detects the presence or execution of artifacts associated with the TrustSink proof-of-concept (deploy.py, cleanup_eam.py, deploy_state.json), which is used to register or remove rogue Entra authentication providers.
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
Detects the creation of a Windows scheduled task where the task name contains the string 'keyroll', often associated with credential rotation or suspicious persistence mechanisms.
Detects the execution of attrib.exe spawned by known Sauron Loader process names (rnpkeys.exe, rnp.exe, or tdwp.exe). The rule flags instances where attrib.exe is executed without its typical command-line arguments (file attribute flags), suggesting it is being used as a surrogate process for injected C2-tasked shellcode.
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
Detects network communication associated with the Rapuncel MaaS (Malware-as-a-Service) campaign, specifically identifying the Command and Control (C2) connection, GitHub Pages-based redirect chains, and subsequent delivery of large, suspicious ZIP archives containing renamed executable/system files.
Detects unauthorized processes (excluding firefox.exe and explorer.exe) accessing or modifying sensitive Firefox browser profile files, specifically places.sqlite (history/bookmarks) and cookies.sqlite (session cookies). This activity is often indicative of credential or session hijacking attempts by malware or malicious scripts.
Detects multiple, rapid execution sequences of Python or PIP utilities using the 'install' flag with specific common library names often used in reconnaissance or malicious activity. This activity is monitored by looking for repetitive installations of targeted packages within a short timeframe on the same endpoint, which may indicate automated tool deployment or preparation for malicious operations.
Detects a dual persistence mechanism where an adversary establishes persistence both via a registry Run key and a scheduled task, both named 'WindowsUpdate'. The rule correlates these events occurring on the same device within a 15-minute window.
Page 67 of 1870


