Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the installation or execution of common remote access tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop) using silent or unattended installation flags. This rule explicitly excludes activity originating from known administrative and management platforms such as Microsoft Intune and SCCM.
Detects instances where rundll32.exe loads a DLL file named Use.dll from a subdirectory named 'ComponentsFolder' within the AppData directory. This pattern is indicative of sandbox evasion techniques used by malware, such as the DarkMe RAT, where the DLL acts as an anti-sandbox gateway to check the execution environment.
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) using either the built-in 'comsvcs.dll' library via 'rundll32.exe' or by requesting specific sensitive process access rights to 'lsass.exe' from unauthorized processes.
Detects user-initiated execution of scripts or binaries directly from the root of a drive letter. This pattern is commonly associated with phishing campaigns delivering malicious payloads via mounted ISO or IMG files, which allow attackers to bypass mark-of-the-web or macro security controls.
Detects the installation or execution of common remote access tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop) using silent or unattended installation flags. This rule explicitly excludes activity originating from known administrative and management platforms such as Microsoft Intune and SCCM.
Detects the use of legitimate Windows binaries (certutil.exe and bitsadmin.exe) to download files from remote URLs to sensitive or common staging directories (Temp, AppData, ProgramData). Attackers frequently abuse these built-in tools for 'living off the land' (LotL) to retrieve malicious payloads or secondary tools while bypassing traditional signature-based detection.
Detects persistence attempts on Windows by monitoring for modifications to common Registry Run/RunOnce keys or the creation of executable files within the user startup directory. The rule excludes common legitimate processes like msiexec.exe, trustedinstaller.exe, and explorer.exe to minimize false positives.
Detects attempts to clear or delete Windows Event Logs using common utilities like wevtutil.exe, PowerShell cmdlets, or direct file system deletion of .evtx files.
Detects instances where an unauthorized or non-standard source process performs cross-process access (such as OpenProcess or similar operations indicative of code injection techniques like CreateRemoteThread or QueueUserAPC) against a sensitive target host process, such as explorer.exe, svchost.exe, or notepad.exe.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility with either system-level privileges ('/ru SYSTEM') or persistent triggers ('/sc onlogon' or '/sc onstart'). The rule filters out commonly trusted parent processes, highlighting potential persistence mechanisms established by unauthorized or unusual processes.
Detects the use of rundll32.exe to invoke the MiniDump function of comsvcs.dll targeting the lsass.exe process. This technique is a well-known living-off-the-land (LotL) method used by adversaries to create a memory dump of LSASS, which can then be exfiltrated and analyzed offline using tools like Mimikatz to extract credentials.
Detects the execution of msbuild.exe targeting project files (.csproj, .proj, .xml) located in user-writable directories such as Temp or Downloads, or containing command-line indicators of inline C# task execution (e.g., UsingTask, CodeTaskFactory). This behavior is commonly used for proxy execution and bypassing application allow-listing via LOLBAS.
Detects Active Directory Certificate Services (AD CS) enrollment events (4886/4887) where a request includes an enrollee-supplied Subject Alternative Name (SAN). This behavior is characteristic of ESC1 certificate template abuse (e.g., using tools like Certipy or Certify) to request certificates that impersonate other users or machine accounts.
Detects the creation of named pipes associated with default Cobalt Strike malleable profiles and common open-source C2 frameworks (e.g., Sliver, Havoc) via EDR pipe-creation telemetry. These pipes are frequently used for SMB beacon communication within compromised networks.
Detects the creation of named pipes associated with default Cobalt Strike malleable profiles and common open-source C2 frameworks (e.g., Sliver, Havoc) via EDR pipe-creation telemetry. These pipes are frequently used for SMB beacon communication within compromised networks.
Detects execution of Mimikatz or usage of its specific command-line arguments (such as sekurlsa or lsadump modules) which indicate attempted credential dumping from system memory.
Detects the request for DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights on domain objects, which are highly sensitive Active Directory permissions required to perform DCSync attacks to harvest credentials from Domain Controllers.
Detects unauthorized modifications to Windows Registry Run/RunOnce keys or the Startup folder. The rule specifically targets persistence attempts where the associated process resides in suspicious directories (Temp, AppData) or uses command-line arguments indicative of script execution (powershell, wscript, mshta, encoded commands, or script extensions). It excludes known legitimate installer behavior involving msiexec or setup processes.
Detects WmiPrvSE.exe spawning child processes within 120 seconds of a Type 3 (Network) logon event. This behavior is a common indicator of remote command execution, frequently used by lateral movement tools like Impacket's wmiexec or similar WMI-based remote execution frameworks.
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests using the weak RC4 encryption type (0x17) from a single account within a 5-minute window. It excludes machine accounts and common system service requests to reduce noise.
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
Page 75 of 1870

