Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the creation of scheduled tasks using Event ID 4698 or command-line execution of schtasks.exe. The rule specifically looks for tasks created in suspicious paths such as AppData or ProgramData, or tasks configured to run with highest privileges and/or marked as hidden, which are common indicators of persistence mechanisms used by adversaries.
Detects anomalous Kerberos service ticket (TGS) requests or successful logons where the corresponding Ticket Granting Ticket (TGT) request (Event ID 4768) is absent within the monitored window. This pattern is a primary indicator of offline-forged Kerberos tickets, such as those generated by Mimikatz, which bypass legitimate KDC interaction for ticket issuance.
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
Detects the creation of scheduled tasks using Event ID 4698 or command-line execution of schtasks.exe. The rule specifically looks for tasks created in suspicious paths such as AppData or ProgramData, or tasks configured to run with highest privileges and/or marked as hidden, which are common indicators of persistence mechanisms used by adversaries.
Detects anomalous Kerberos service ticket (TGS) requests or successful logons where the corresponding Ticket Granting Ticket (TGT) request (Event ID 4768) is absent within the monitored window. This pattern is a primary indicator of offline-forged Kerberos tickets, such as those generated by Mimikatz, which bypass legitimate KDC interaction for ticket issuance.
This rule detects the suspicious execution of rundll32.exe or regsvr32.exe, which are commonly abused as Living-off-the-Land Binaries (LOLBins). It identifies potential malicious activity by analyzing command-line arguments for patterns like remote URL requests, usage of scrobj.dll, JavaScript protocols, or specific Squiblydoo attack patterns. Additionally, it monitors for these binaries being executed by parents other than explorer.exe, which is indicative of potential process injection or proxy execution.
Detects attempts to access or dump the memory of the Local Security Authority Subsystem Service (LSASS) process, a technique commonly used by adversaries to harvest domain credentials and clear-text passwords from memory.
Detects lateral movement techniques leveraging Windows Management Instrumentation (WMI). The rule identifies instances where the WMI provider host, WmiPrvSE.exe, spawns common administrative or interactive shell tools (e.g., cmd.exe, powershell.exe). This pattern is consistent with the abuse of Win32_Process.Create() via WMI/DCOM/RPC for remote command execution, a method frequently utilized by frameworks like Impacket (wmiexec.py) for fileless, agentless lateral movement.
This rule detects potential RDP brute force and password spraying attacks by correlating Windows Event ID 4625 (failed logins) and 4624 (successful logins) via RDP (Logon Type 10). It monitors for high volumes of failed attempts across multiple accounts or high volume of failed attempts from a single source, followed by successful authentication from the same source.
Detects unauthorized usage of the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, which are required for the DCSync technique. The rule monitors for Windows Event ID 4662 (Object Access) where a non-domain controller account attempts these replication operations, typically indicative of credential dumping and domain compromise.
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (LSASS) process with access rights consistent with credential dumping (e.g., PROCESS_VM_READ, PROCESS_ALL_ACCESS). This rule also specifically flags the use of well-known tools and techniques such as Mimikatz, ProcDump, and the abuse of rundll32.exe with comsvcs.dll for memory extraction, which is indicative of OS Credential Dumping (T1003.001).
This rule detects persistence mechanisms by monitoring additions to Windows Registry Run keys or files created in the user's Startup directory. It specifically flags entries that target suspicious locations (e.g., Temp, AppData, Public) or attempt to execute encoded commands using PowerShell or CMD.
This rule detects potential lateral movement indicative of PsExec or similar administrative tools. It identifies the combination of remote service installation (often using ADMIN$ or Temp paths), access to administrative shares (ADMIN$ or C$), and the execution of a process spawned by services.exe, which is characteristic of the remote service control manager performing remote service starts.
This rule detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to perform actions associated with ransomware, such as deleting volume shadow copies, deleting the backup catalog, or disabling system recovery features. This is a common precursor to data encryption to prevent the user from restoring files.
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) where a single user requests tickets for multiple distinct Service Principal Names (SPNs) using weak RC4 (0x17) encryption. This behavior is highly characteristic of Kerberoasting, a technique used by adversaries to harvest service account tickets for offline cracking.
Detects the abuse of signed Windows system binaries (LOLBins: certutil, mshta, regsvr32, rundll32, bitsadmin, msiexec) through the identification of command-line arguments that suggest malicious activity, such as downloading remote content, decoding files, executing scriptlets, or loading DLLs from temporary storage directories.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell. The rule looks for command-line arguments referencing AMSI-related memory structures, methods, and DLLs such as AmsiUtils, AmsiScanBuffer, AmsiInitFailed, and amsi.dll. Bypassing AMSI is a common technique used by attackers to execute malicious scripts and deploy fileless payloads, such as Cobalt Strike or Sliver, while avoiding detection by endpoint security solutions.
Detects potential Golden SAML activity by correlating Azure AD SAML sign-in events for privileged accounts with a lack of corresponding server-side ADFS authentication logs, unusual SAML issuer URIs, lack of on-premises authentication logs, or evidence of direct access to ADFS token-signing certificate private key material.
Detects the execution of native Windows utilities such as vssadmin, wmic, wbadmin, and bcdedit used to delete volume shadow copies, the backup catalog, or disable system recovery boot policies. This activity is a common precursor to ransomware encryption to prevent data restoration.
Detects the use of token manipulation APIs (DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser), the 'runas' command for credential switching, or the execution of known security token manipulation tools (e.g., incognito, Tokenvator, Invoke-TokenManipulation). This activity is commonly associated with privilege escalation and token theft.
Detects the use of data archival utilities (7zip, WinRAR) or command-line cloud synchronization tools (Rclone) to stage files in common temporary directories, immediately followed by network connections to known cloud storage endpoints. This pattern is characteristic of pre-encryption exfiltration activities often seen in ransomware campaigns.
Page 76 of 1870
