Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
Detects the unauthorized creation of script or executable files in the Windows Startup directory by .NET or Python runtime processes, specifically targeting the exploitation pattern of CVE-2026-25592. This vulnerability allows an AI agent host to bypass sandbox isolation and write files to the host filesystem, potentially establishing persistence.
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
Page 84 of 1870


