Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
Detects execution of rundll32.exe or regsvr32.exe with potentially malicious command-line arguments, including references to external URLs, protocol handlers like javascript:, or loading DLLs from user-writable directories (Temp, AppData, Downloads). This behavior is characteristic of Living-off-the-Land (LotL) techniques used to proxy execution and bypass application control or security monitoring.
Detects Windows Event 4662 indicating the use of DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights from a host that is not a known domain controller. This behavior is highly indicative of credential dumping via DCSync, commonly associated with tools like Mimikatz.
This rule detects potential lateral movement via Remote Desktop Protocol (RDP) by identifying a single user account establishing RemoteInteractive (logon type 10) sessions to three or more distinct destination hosts within a 15-minute timeframe. This pattern is indicative of an attacker attempting to traverse a network from a compromised host.
Detects instances where one process initiates an injection mechanism (such as CreateRemoteThread, QueueUserAPC, or NtMapViewOfSection) into another process. The rule specifically alerts when these actions target common, high-value, or frequently abused processes such as explorer.exe, svchost.exe, or web browsers (chrome.exe, firefox.exe, msedge.exe), which are common targets for maintaining persistence or evading detection.
Detects anomalous lateral movement behavior by monitoring Windows Event 4624 (Logon Type 3) using NTLM authentication. The rule triggers when a single user account authenticates to five or more distinct hosts within a five-minute window, a pattern frequently associated with Pass-the-Hash attacks where captured credentials are used to spread across a network.
Detects non-SYSTEM processes enabling SeDebugPrivilege or SeImpersonatePrivilege shortly before launching a process as the SYSTEM user. This behavior is highly indicative of token manipulation and impersonation techniques (e.g., Potato-family exploits) used to elevate privileges from a standard or administrative account to SYSTEM.
Detects attempts to disable security services (Windows Defender, EDR agents), modify audit policies via auditpol, or stop/clear the Windows Event Log service. This behavior is a common precursor to post-compromise activity intended to blind defenders and conceal malicious actions.
Detects an attempt to perform Active Directory replication (DS-Replication-Get-Changes or DS-Replication-Get-Changes-All) initiated by a machine that is not a recognized Domain Controller. This is a common indicator of credential dumping or unauthorized domain information gathering.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
This rule detects the creation of scheduled tasks using either 'schtasks.exe' or PowerShell ('powershell.exe', 'pwsh.exe') with suspicious parameters. It flags tasks created in temporary directories (e.g., AppData, Temp, ProgramData, Windows\Temp) or tasks executed with 'highest' privileges or hidden configurations, often used for persistence or lateral movement.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
Detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos TGS requests (Event ID 4769) for tickets encrypted with RC4 (0x17) within a short timeframe. The rule tracks the count of requests and the diversity of Service Principal Names (SPNs) requested by a specific user account, excluding machine accounts.
Detects potential persistence mechanisms on Windows systems by monitoring for the creation or modification of Registry 'Run' or 'RunOnce' keys, as well as the creation of files within the Windows Startup folder. These actions are commonly used by adversaries to ensure malicious code executes automatically upon user login or system startup.
Detects execution of regsvr32.exe with command-line arguments that include a remote URL ('/i:http...') combined with silent, unregistered, and notification-free execution flags ('/s', '/u', '/n'). This behavior is characteristic of the 'Squiblydoo' technique, where attackers use Regsvr32 to execute arbitrary scriptlets from remote servers to bypass application whitelisting.
Detects instances of rundll32.exe being used with suspicious command line arguments, such as referencing JavaScript, loading Control Panel applets (.cpl) via shell32.dll from non-standard locations, or executing DLLs directly from user-writable directories (Temp, AppData, Downloads, ProgramData). These patterns are common techniques used by adversaries to proxy execution and evade detection.
Detects potential lateral movement and persistence activities by identifying suspicious Windows service installations via event ID 7045. The rule flags services with suspicious names or paths (e.g., Temp folders, Public directory) and correlates them with incoming SMB connections (port 445) or services spawned directly by services.exe from suspicious locations, aggregated by host and remote IP.
Page 80 of 1870

