Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects modifications to Windows Registry persistence locations (Run, RunOnce, Winlogon Shell/Userinit) where the assigned executable path is located within high-risk directories such as Temp, AppData, or Users Public folders. This is a common technique used by malware for persistence.
This rule detects instances of Kerberos Ticket-Granting Ticket (TGT) requests (Event IDs 4768 and 4769) that utilize the legacy RC4 encryption type (0x17). In modern Active Directory environments where AES is the standard for Kerberos, the use of RC4 can be a strong indicator of a Golden Ticket attack or other unauthorized ticket forging activities, as adversaries often force a downgrade to RC4 for easier offline cracking.
Detects Microsoft Windows Event ID 4662 (Object Access) where specific GUIDs associated with sensitive Active Directory rights (specifically, those related to DCSync or sensitive extended rights) are accessed. The rule filters out events originating from Domain Controllers to identify potentially anomalous access patterns from non-DC endpoints.
Detects modifications to Windows Registry persistence locations (Run, RunOnce, Winlogon Shell/Userinit) where the assigned executable path is located within high-risk directories such as Temp, AppData, or Users Public folders. This is a common technique used by malware for persistence.
Detects the loading of common Windows system DLLs (e.g., version.dll, dbghelp.dll) from suspicious, non-standard directory paths. Such behavior is often indicative of DLL side-loading or hijacking attempts, where an adversary places a malicious DLL with the same name as a legitimate one in a writable directory to influence application execution.
Detects the use of native Windows binaries such as vssadmin.exe, wmic.exe, bcdedit.exe, and wbadmin.exe to inhibit system recovery by deleting shadow copies, clearing backup catalogs, or disabling automatic system recovery.
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from non-reputable/non-Microsoft sources to suspicious directories such as Temp, AppData, or ProgramData, which is a common technique for ingress tool transfer during malware delivery.
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from non-reputable/non-Microsoft sources to suspicious directories such as Temp, AppData, or ProgramData, which is a common technique for ingress tool transfer during malware delivery.
Detects suspicious activity associated with Cobalt Strike Beacon communication, specifically monitoring for known default named pipes and specific user-agent strings commonly used by Cobalt Strike in HTTP/S traffic.
Detects the initiation of a new process where the effective user context is SYSTEM, but the originating process was launched by a non-privileged user account. This behavior is indicative of token manipulation techniques such as token impersonation or theft (e.g., via DuplicateTokenEx or ImpersonateLoggedOnUser) to escalate privileges to SYSTEM.
Detects instances where an alert marked as process injection (T1055) involves an action process that is unsigned and differs from the actor process image, suggesting potential execution of an unauthorized or malicious payload masked by process injection techniques.
Detects the presence of specific Go build path metadata associated with the sckit Go implant, including modules and internal package structures, within an executable or file.
This rule detects potential persistence mechanisms involving the creation of 'Locked' registry keys within Software\Classes and subsequent use of Run registry keys that reference 'Locked://' URIs. It also identifies suspicious execution of rundll32.exe utilizing specific CLSID-based command line arguments associated with the '{CFDC57BA-1705-45AF-BA10-EFC3D592982B}' identifier, often linked to malicious activity patterns.
Detects instances where the Firefox browser or its plugin container process initiates a DNS query for domains containing 'pdf.gusercontent.com', which is a known lookalike pattern used to masquerade as legitimate Google infrastructure for potential command and control or data exfiltration activities.
Detects the creation of suspicious scheduled tasks using the Windows schtasks.exe utility. The rule flags tasks that are configured to run as SYSTEM, include PowerShell encoded commands, or target directories commonly used for persistence such as Temp, AppData, or Public.
This rule detects attempts by an attacker to disable or modify Windows security software and features. It monitors for three distinct behaviors: execution of 'Set-MpPreference' to modify Windows Defender settings (exclusions or real-time monitoring), execution of 'sc.exe' to stop security-related services (such as EDR or AV services), and direct modification of Windows registry keys to disable Windows Defender components.
Detects the abuse of Windows Management Instrumentation (WMI) to execute processes via wmic.exe or WmiPrvSE.exe, often combined with obfuscated command-line arguments such as encoded PowerShell or CMD commands.
Detects the execution of search-ms or search protocol URIs that contain a 'crumb' parameter combined with either a 'displayname' parameter or remote path indicators (such as WebDAV/UNC paths). This technique is commonly used by adversaries to redirect Windows Search to a remote, malicious location while masking the source by spoofing the displayed name or path to trick users.
Detects unauthorized processes (other than known browsers like Chrome, Edge, or Firefox) attempting to access sensitive browser files such as 'Login Data', 'Cookies', or 'Web Data'. This behavior is commonly associated with credential stealing or browser session hijacking.
Detects suspicious modifications to Windows Registry keys associated with URL protocol handlers or automatic startup mechanisms. Adversaries often use custom URL schemes or registry run keys to maintain persistence or execute malicious code when a specific protocol is invoked or upon user logon.
Detects user-initiated execution of scripts or binaries directly from the root of a drive letter. This pattern is commonly associated with phishing campaigns delivering malicious payloads via mounted ISO or IMG files, which allow attackers to bypass mark-of-the-web or macro security controls.
Page 74 of 1870

