Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects PowerShell processes (including pwsh and ISE) referencing Anti-Malware Scan Interface (AMSI) related classes and methods in their command line arguments. This is a common indicator of an attempt to interact with or manipulate AMSI, often used to bypass or disable security scanning during the execution of malicious scripts.
Detects the creation or connection of named pipes that match known default and common malleable C2 profile patterns used by the Cobalt Strike post-exploitation framework. These named pipes are frequently utilized by Cobalt Strike beacons for inter-process communication, SMB/TCP beacon functionality, and staging during post-exploitation activities.
This rule detects PowerShell processes (including pwsh and ISE) referencing Anti-Malware Scan Interface (AMSI) related classes and methods in their command line arguments. This is a common indicator of an attempt to interact with or manipulate AMSI, often used to bypass or disable security scanning during the execution of malicious scripts.
Detects instances where the WMI service (wmiprvse.exe) spawns common command-line or system tools such as cmd.exe, powershell.exe, or rundll32.exe. This behavior is often indicative of lateral movement or remote command execution via WMI.
Detects common suspicious PowerShell command-line patterns often used for malicious purposes, including base64-encoded command execution, hidden-window execution with common evasion flags, and the use of download/execution cmdlets for in-memory payload delivery.
This rule detects potential lateral movement by identifying a single user account authenticating to three or more distinct hosts using NTLM via network (LogonType 3) or impersonation (LogonType 9) logons, which is characteristic of credential-based movement across a network.
This rule monitors for an abnormally high number of Kerberos Ticket Granting Service (TGS) requests using the RC4-HMAC encryption type (0x17) from a single IP address to various service accounts. This pattern is indicative of Kerberoasting, a technique where attackers attempt to obtain service tickets to crack service account passwords offline.
This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys that point to executables or scripts located within suspicious user-writable directories such as AppData, Temp, or Users Public. This is a common technique used by adversaries to establish persistence on a compromised host.
Detects attempts to disable, modify, or stop security software and endpoint protection services. The rule monitors for registry changes to Windows Defender settings, manual service management commands (sc, net) targeting security processes, and PowerShell execution using 'Set-MpPreference' to disable protection features.
Detects instances where a process attempts to access the memory of the Local Security Authority Subsystem Service (LSASS.exe) with suspicious access rights often associated with credential dumping. The rule excludes known benign processes such as antivirus and debugging tools.
Detects the execution of known Windows system binaries (rundll32, regsvr32, mshta, msiexec) with command-line arguments indicative of proxy execution or script-based attacks. The rule identifies patterns commonly associated with downloading or executing remote payloads, including the use of URLs, JavaScript, VBScript, or specific DLL exports designed to execute code indirectly or from a remote source.
Detects the creation or modification of scheduled tasks that exhibit suspicious characteristics, such as using common temporary directories, executing PowerShell with encoded commands, running tasks as SYSTEM, or using tasks that attempt to hide by using unusual naming conventions. These techniques are often used by adversaries to establish persistence or facilitate execution in a stealthy manner.
Detects the invocation of Active Directory replication rights by monitoring Event 4662 for specific directory service replication GUIDs (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All). This behavior is characteristic of adversary techniques such as DCSync used by tools like Mimikatz lsadump::dcsync or Impacket secretsdump to extract domain password hashes.
Detects potential C2 beaconing activity by identifying repeated network connections to the same external host that exhibit consistent payload sizes (low variance) and frequency, or by flagging HTTP requests containing default URI patterns associated with Cobalt Strike profiles.
This rule detects a credential-based attack where a single source IP performs multiple failed RDP (LogonType 3/10) attempts against various user accounts, followed by a successful authentication from the same source within an hour. This pattern is indicative of password spraying or brute-forcing followed by successful lateral movement via Remote Desktop.
Detects Sysmon Event ID 10 (ProcessAccess) events where a process opens lsass.exe with a GrantedAccess mask matching known credential-dumping access rights (e.g. PROCESS_VM_READ combinations used by Mimikatz/ProcDump-style tooling), excluding common legitimate EDR/AV/diagnostic source processes.
This rule monitors for process creation events where the parent process is identified as the WMI Provider Host (wmiprvse.exe) or the Windows Management Instrumentation Command-line (wmic.exe) tool, executing a Win32_Process creation command. This pattern is commonly used by adversaries for remote execution and lateral movement.
Detects potential Kerberoasting activity by identifying anomalous behavior where a single account requests 5 or more unique Kerberos Service Principal Name (SPN) tickets within a 5-minute window, excluding common service accounts and krbtgt ticket requests. This behavior is indicative of an attacker attempting to enumerate and obtain tickets for multiple services for offline brute-force password cracking.
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in PowerShell by monitoring for common bypass techniques such as reflective loading of AmsiUtils, tampering with the amsiInitFailed field, or memory patching of AmsiScanBuffer via Script Block Logging (EventID 4104).
Detects unauthorized Active Directory replication requests (DCSync) by monitoring Event ID 4662 for specific directory replication GUIDs originating from computers not identified as domain controllers or by accounts not pre-approved for replication tasks.
Detects the creation of scheduled tasks using schtasks.exe or Event ID 4698 that involve scripting interpreters (powershell, wscript, mshta, cmd) and suspicious command line arguments often associated with malicious activity, such as encoded commands, hidden windows, or network resource access, specifically when executing under the SYSTEM account context.
Page 82 of 1870
