Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects the execution of browser automation and testing tools (such as Playwright, Puppeteer, Selenium, and various browser drivers) when initiated by common, non-development-related parent processes like Microsoft Office applications, Explorer, or service hosts. This behavior is indicative of potential malicious activity, such as automated credential harvesting or unauthorized web interaction initiated by a compromised document or process.
Detects the execution of known living-off-the-land binaries or network utilities initiated by or involving processes related to the Semantic Kernel framework (e.g., SKAgent, kernel.run). This pattern is often indicative of automated execution, potentially associated with agent-based activity or malicious orchestration leveraging AI framework components.
Detects anomalous executions of ctfmon.exe that deviate from known-good parent process patterns, such as unexpected parent processes (e.g., script hosts, LOLBins) or execution from locations other than C:\Windows\System32\ctfmon.exe. This rule is designed to help identify potential masquerading or process injection associated with exploitation attempts, including CVE-2026-45586.
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
This rule monitors for various indicators of compromise (IOCs) including malicious domains, IP addresses, specific URI paths, file names, and file hashes. It aggregates telemetry from network, file, process, and certificate events to detect potential threats interacting with known bad infrastructure or executing suspicious files associated with malware campaigns.
Detects the use of PowerShell to modify Microsoft Defender antivirus preferences by adding exclusion paths or processes. This behavior is indicative of an attacker attempting to bypass security software detection by excluding their malicious tools or staging areas from scanning.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Detects multiple reconnaissance commands executed by PowerShell processes running as the SYSTEM account. This behavior is indicative of an attacker attempting to enumerate domain trusts, group memberships, or user sessions on a host to facilitate lateral movement or privilege escalation.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the execution of 'LevelInstaller.exe' with specific installation arguments ('--action install --force --key') in conjunction with the presence of the 'level.exe' binary in its designated Program Files directory. The rule optionally identifies related scheduled task creation for 'Level Watchdog' and network activity associated with the 'level.io' domain or specific IP address.
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
This rule detects rundll32.exe executing a DLL from the ProgramData directory and subsequently establishing five or more outbound network connections to external IP addresses over non-standard ports (excluding 80 and 443) within a one-hour window. This behavior is indicative of a potential malware beaconing or data staging activity using a proxy binary to evade detection.
Page 73 of 1866





