Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution of the Microsoft HTML Application host (mshta.exe) when it is used to launch scripts from remote URLs (http/https/ftp) or when it spawns common command-line shells and scripting engines, which is a common indicator of living-off-the-land techniques used to execute malicious payloads.
This rule detects various forms of process injection (Remote Thread, APC, Map View of Section) targeting common, high-value Windows processes such as explorer.exe, lsass.exe, and web browsers. This behavior is a common technique used by attackers to gain persistence, elevate privileges, or execute code within the context of legitimate system or user-level processes to evade detection.
Detects unauthorized attempts by processes to access the memory of sensitive Windows system processes, specifically LSASS.exe or winlogon.exe, using suspicious access masks associated with memory dumping or credential harvesting.
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
Detects the abuse of signed Windows system binaries regsvr32.exe and rundll32.exe for proxy execution, defense evasion, and credential access. The rule identifies suspicious command-line patterns including Squiblydoo (regsvr32 with remote scriptlets), rundll32 executing JavaScript via mshtml.dll, rundll32 performing LSASS credential dumping via comsvcs.dll, and the loading of DLLs from untrusted user-writable locations like Temp or Downloads folders.
Detects Kerberos service ticket requests (EventID 4769) that utilize RC4 encryption (0x17) instead of the more secure AES encryption. Attackers often force RC4-HMAC when requesting service tickets for accounts with Service Principal Names (SPNs) because these tickets are susceptible to offline brute-force attacks to recover service account passwords. This technique is a common precursor to lateral movement and privilege escalation in Active Directory environments.
Detects potential Pass-the-Hash (PtH) activity by monitoring for NTLM network logons (Logon Type 3) that are associated with a blank WorkstationName, often indicating spoofing. This pattern is correlated with the assignment of special privileges (EventID 4672) to capture scenarios where stolen NTLM hashes are replayed for lateral movement into a system.
Detects the abuse of signed Windows system binaries regsvr32.exe and rundll32.exe for proxy execution, defense evasion, and credential access. The rule identifies suspicious command-line patterns including Squiblydoo (regsvr32 with remote scriptlets), rundll32 executing JavaScript via mshtml.dll, rundll32 performing LSASS credential dumping via comsvcs.dll, and the loading of DLLs from untrusted user-writable locations like Temp or Downloads folders.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the task execution path points to common script interpreters (PowerShell, WScript, CScript, MSHTA, Rundll32) or is located in common user-writable directories (Users, Temp, AppData). Additionally, it flags tasks configured to execute under the 'SYSTEM' account, which is a common technique used to achieve persistence with elevated privileges.
Detects the execution of PowerShell commands that leverage obfuscation or evasion techniques such as Base64 encoded commands, hidden window styles, in-memory script downloads via IEX, and common string obfuscation methods like backtick insertion, character concatenation, and casting. These techniques are frequently used by adversaries to bypass command-line monitoring and execute malicious payloads.
Detects the creation of a new Windows service (EventID 7045) where the binary path references the ADMIN$ share, contains known remote execution tool artifacts (e.g., PSEXESVC, PAExec), or uses a randomized/GUID-like naming convention. This pattern is indicative of classic SMB-based lateral movement where an adversary performs remote code execution via service installation following credential compromise.
Detects the spawning of cmd.exe, powershell.exe, or powershell_ise.exe by the WMI Provider Host (wmiprvse.exe). This pattern is frequently used for fileless lateral movement, as threat actors leverage WMI (Win32_Process.Create) to execute remote commands which manifests as wmiprvse.exe launching a shell on the target host.
Detects the use of legitimate Windows system utilities certutil.exe and bitsadmin.exe to perform remote file downloads or decode remote content. Adversaries often use these dual-use tools to bypass network security controls by masquerading as standard system processes for staging second-stage payloads.
Detects the loading of suspicious kernel drivers (Sysmon Event ID 6) that are unsigned, have invalid/revoked signatures, or are located in user-writable directories (e.g., Temp folders). This rule aims to identify Bring Your Own Vulnerable Driver (BYOVD) attacks, where adversaries load vulnerable drivers to escalate privileges or bypass security controls.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by monitoring script block logs for specific patterns used to disable or manipulate memory scanning mechanisms, a common precursor to executing malicious, memory-resident payloads.
Detects Kerberos ticket requests (AS-REQ/TGS-REQ) that exhibit characteristics of a forged Golden Ticket, specifically the use of legacy RC4 (0x17) encryption in environments where AES is typically preferred, non-standard ticket options (0x40810000), and requests for accounts or services that lack a corresponding legitimate authentication event. This detection aims to identify the post-compromise phase where an adversary uses a forged TGT to impersonate domain accounts.
Detects the use of native Windows utilities such as vssadmin, ntdsutil, or diskshadow to create volume shadow copies for the purpose of accessing or extracting the ntds.dit Active Directory database file. This activity is a common indicator of credential theft attempts where adversaries bypass file access protections to offline-process the database and retrieve password hashes.
Detects unauthorized access attempts to SYSTEM-level processes (winlogon.exe, services.exe) using specific access rights such as PROCESS_DUP_HANDLE or PROCESS_QUERY_INFORMATION. This behavior is indicative of token stealing or impersonation attempts often utilized by tools like JuicyPotato, RoguePotato, and PrintSpoofer to escalate privileges to SYSTEM.
Detects potential process injection attempts where a browser or Office application attempts to write to the memory or create a remote thread within high-value or trusted system processes like svchost.exe or explorer.exe. This activity is indicative of defense evasion techniques such as DLL or PE injection.
Detects suspicious process access to the Local Security Authority Subsystem Service (lsass.exe) with access masks commonly associated with credential dumping techniques. The rule specifically monitors for high-privileged access requests by unauthorized processes, excluding known legitimate tools and system services, to identify attempts to extract cached authentication materials such as NTLM hashes or Kerberos tickets.
Page 81 of 1870
