Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects attempts to bypass PowerShell execution policies either through command-line arguments ('-ExecutionPolicy Bypass' or '-ExecutionPolicy Unrestricted') or by modifying PowerShell execution policy registry keys. This behavior is commonly used by adversaries to execute unsigned or malicious scripts, circumventing default system security restrictions.
This rule monitors network, DNS, and HTTP activity to identify connections to known infrastructure associated with the ClickFix social engineering campaign and Vidar infostealer malware. The rule correlates device network events, HTTP request events, and DNS queries against a list of known malicious domains, IP addresses, and URL patterns used for C2, staging, and lures.
Detects high-volume network activity from a single device/process to public IP addresses over common ports (80, 443) or UDP protocol. This behavior is indicative of potential command and control communication, automated data exfiltration, or a scanning attempt.
This rule detects potential ransomware activity by correlating a rapid burst of file creation, modification, or renaming events across multiple directories with prior execution of defense evasion commands, such as deleting volume shadow copies or terminating security-related processes. This sequence is characteristic of ransomware operators attempting to disable recovery options and security protections before commencing mass file encryption.
Detects unauthorized mass clearing of Windows Event Logs using wevtutil or PowerShell cmdlets. This behavior is often observed in ransomware campaigns (e.g., Nova, Gentlemen) as an anti-forensic measure to hinder incident response and investigation by removing audit trails across significant log channels like Security, System, and PowerShell.
Detects the execution of msiexec.exe initiated by a Windows script host (wscript.exe or cscript.exe) in close temporal proximity to a suspicious PowerShell command. The PowerShell command includes flags common in obfuscated or downloader scripts such as '-NoProfile' combined with file manipulation or sleep cmdlets, which may indicate a multi-stage infection or payload delivery chain.
Detects suspicious activities associated with ysoserial.net gadget chain exploitation targeting SharePoint's w3wp.exe process. The rule correlates the loading of specific .NET assemblies (PresentationFramework, System.Xaml, System.Data.Services) with the subsequent execution of command shells (cmd, powershell) or the presence of common ysoserial.net-related strings (ActivitySurrogateSelector, LosFormatter) within command lines originating from the w3wp.exe process, indicating a potential web shell.
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
Detects the execution of known tunneling binaries (ngrok, cloudflared) or network connections to tunneling service domains (ngrok.io, ngrok-free.app, trycloudflare.com), which are frequently used to establish unauthorized remote access or bypass perimeter security controls.
Detects high-frequency outbound network connections to known large language model (LLM) API providers (OpenAI, xAI, Anthropic) originating from a single endpoint within a short timeframe. This activity is indicative of potential API key theft, where an attacker uses a compromised legitimate key to exhaust credit quotas or exfiltrate data via unauthorized API calls, bypassing the intended application.
Detects instances where the suspicious binary 'x47_bot.exe' performs process injection or hollows a process, followed by an attempt to gain or elevate privileges (such as via UAC bypass, token manipulation, or privilege checking) on the same host within a 15-minute window.
Detects instances where the suspicious binary 'x47_bot.exe' performs process injection or hollows a process, followed by an attempt to gain or elevate privileges (such as via UAC bypass, token manipulation, or privilege checking) on the same host within a 15-minute window.
Detects x47.c botnet compiled outputs x47_bot.exe/x47_bot.dll or references to the x47.c_FF_v4.1 package directory
Detects high-frequency outbound network connections to known large language model (LLM) API providers (OpenAI, xAI, Anthropic) originating from a single endpoint within a short timeframe. This activity is indicative of potential API key theft, where an attacker uses a compromised legitimate key to exhaust credit quotas or exfiltrate data via unauthorized API calls, bypassing the intended application.
Detects an exploitation chain originating from a Chrome browser process, characterized by the execution of an anomalous child process followed by the creation of an executable file named 'chrome_cleanup.exe' within a short time window. This sequence is indicative of multi-stage exploitation, involving remote code execution via browser vulnerability and subsequent privilege escalation.
Detects a potential brute force or password spraying attempt by identifying instances where a single IP address targets 8 or more distinct user accounts with failed authentication attempts (Event ID 4625) within a 30-minute window.
Page 69 of 1870



