Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects potential post-compromise activity related to a campaign using MSP360-masqueraded installers and ScreenConnect remote access tools. It performs an IOC sweep across device file events for known malicious file hashes (associated with installers and post-compromise utilities) and device network events for connections to known malicious domains used for command and control.
Detects the creation or modification of Windows service registry keys where the ImagePath points to a binary with a non-standard file extension (e.g., .s, .c, .l). This behavior is associated with the NeedyMantis malware family, which utilizes non-standard naming for persistence mechanisms to evade basic detection.
Detects unauthorized processes accessing sensitive credential storage files (e.g., 'Login Data', 'Cookies', 'Local State') from known Chromium-based browser profile directories. This activity is indicative of credential harvesting by infostealer malware attempting to exfiltrate browser data before performing decryption.
Detects a sequence of events where a user clicks a shared link to an AI chatbot conversation followed closely (within 15 minutes) by the execution of potentially malicious processes (mshta, powershell, cmd) that include suspicious command-line patterns indicative of ClickFix-style social engineering.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Detects the modification of the wsl.exe binary from its installed location.
Attackers can replace the legitimate wsl.exe binary with a malicious payload in its place, which is then executed when the user runs WSL, acting as a proxy execution and defense evasion technique.
Attackers can replace the legitimate wsl.exe binary with a malicious payload in its place, which is then executed when the user runs WSL, acting as a proxy execution and defense evasion technique.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Detects the creation, modification or deletion of a WMI permanent event subscription using Sysmon EventID 21.
Detects anomalous lateral movement behavior where a successful NetScaler VPN or gateway session is followed immediately by internal remote service logons (RDP, SSH, WinRM) or network connections from the same source IP. This pattern is indicative of potential exploitation of Citrix NetScaler vulnerabilities (e.g., CVE-2026-88771, CVE-2026-88772) or credential abuse to move laterally into the internal environment.
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
Detects the execution of the 'rnpkeys.exe' file from the 'C:\ProgramData\keyroll\' directory. The location and filename are highly atypical and could indicate unauthorized tool usage, potential persistence, or malicious activity.
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
Detects instances where a process writes to known persistence locations, including Windows Registry Run keys, the Windows Startup folder, Linux shell profile configuration files (.bashrc/.bash_profile), and system-level task directories (cron and systemd units). This activity is often indicative of malicious persistence mechanisms, such as those used by compromised AI agents or backdoors to survive system reboots.
The following analytic identifies a possible non-common browser process accessing its browser user data profile.
This tactic/technique has been observed in various Trojan Stealers, such as SnakeKeylogger, which attempt to gather sensitive browser information and credentials as part of their exfiltration strategy.
Detecting this anomaly can serve as a valuable pivot for identifying processes that access lists of browser user data profiles unexpectedly.
This detection uses a lookup file `browser_app_list` that maintains a list of well known browser applications and the browser paths that are allowed to access the browser user data profiles.
This tactic/technique has been observed in various Trojan Stealers, such as SnakeKeylogger, which attempt to gather sensitive browser information and credentials as part of their exfiltration strategy.
Detecting this anomaly can serve as a valuable pivot for identifying processes that access lists of browser user data profiles unexpectedly.
This detection uses a lookup file `browser_app_list` that maintains a list of well known browser applications and the browser paths that are allowed to access the browser user data profiles.
The following analytic identifies potential DLL search order hijacking or DLL sideloading by detecting known Windows libraries loaded from non-standard directories. It leverages Sysmon EventCode 7 to monitor DLL loads and cross-references them with a lookup of known hijackable libraries. This activity is significant as it may indicate an attempt to execute malicious code by exploiting DLL search order vulnerabilities. If confirmed malicious, this could allow attackers to gain code execution, escalate privileges, or maintain persistence within the environment.
Detects a suspected ClickFix social engineering attack where a user is tricked into pasting malicious commands into Windows Terminal, leading to a PowerShell download, followed by the appearance of specific known malicious artifacts (LockScreenContentServer.exe, dui70.dll, or 1.bat) within 15 minutes on the same device.
Page 7 of 1866



