Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
Detects command-line activity indicative of attempts to perform a DCSync attack, a method used to simulate the replication process of a Domain Controller to extract sensitive Active Directory credentials, including password hashes, using tools like Mimikatz or DSInternals.
Detects the creation of a scheduled task using 'schtasks.exe' that involves suspicious command-line patterns, specifically tasks pointing to potentially volatile directories (temp, appdata, programdata) or tasks executing PowerShell/CMD with common obfuscation/execution arguments such as encoded commands, hidden window styles, or base64 decoding.
Detects potential abuse of Windows Management Instrumentation (WMI) for process execution. It monitors for wmic.exe creating processes, PowerShell cmdlets Invoke-WmiMethod or Invoke-CimMethod used for remote execution, and unexpected process spawns from the WmiPrvSE.exe provider service, which are common indicators of lateral movement and remote command execution.
This rule detects the execution of common tools and commands used to perform Kerberoasting, a technique where attackers request Kerberos service tickets for user accounts with Service Principal Names (SPNs) in order to perform offline brute-force attacks to recover plaintext credentials. The rule specifically monitors process creation events for known offensive security tools like Rubeus, as well as specific command-line arguments for 'setspn.exe' and various scripts that can be used to identify potential Kerberoasting targets.
This rule detects persistence mechanisms involving the modification of Windows Registry 'Run' keys or the addition of executable/script files to the Windows Startup folder. It flags suspicious file types (vbs, js, hta, ps1, lnk) or the usage of common living-off-the-land binaries (wscript, cscript, powershell, mshta) when interacting with these persistence locations, while filtering out known benign processes like trustedinstaller.exe and explorer.exe.
Detects the creation of WMI event subscriptions via wmic.exe, PowerShell, or the compilation of MOF files. These techniques are commonly used by adversaries to establish persistence or execute malicious payloads by binding event filters to event consumers.
Detects attempts to bypass or disable the Antimalware Scan Interface (AMSI) in PowerShell by identifying specific commands used to manipulate the AmsiUtils class or its field values in memory.
Detects the use of legitimate Windows binaries (certutil.exe and bitsadmin.exe) to download files from remote URLs or perform encoding/decoding operations in suspicious directories (Temp, AppData). This activity is commonly used by adversaries for stage-one malware delivery or tool ingress.
Detects instances of rundll32.exe or regsvr32.exe executing from suspicious locations or with suspicious command-line arguments (e.g., URLs, JavaScript, or script file extensions) initiated by an unsigned process. This is a common technique used to proxy malicious code execution while evading security monitoring.
Detects the execution of PowerShell processes using suspicious command-line flags, encoding, or built-in .NET network download methods (e.g., IEX, Net.WebClient, DownloadString). The rule excludes signed PowerShell binaries and common system management tools like SCCM or monitoring agents to reduce false positives.
This rule detects unauthorized or suspicious cross-process access attempts by monitoring relationships between source and target processes. It specifically flags instances where common target processes (e.g., browsers or core system processes) are accessed by a source process that is not on a known allowlist of legitimate parent/child or service-related processes. This pattern is often indicative of process injection or unauthorized memory access attempts.
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
Detects the creation of Windows Management Instrumentation (WMI) Event Filter, Event Consumer, or FilterToConsumerBinding objects. Attackers use these objects to create event subscriptions that trigger malicious code or scripts upon specific system events, providing a stealthy and persistent execution mechanism.
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
Detects the Microsoft HTML Help executable (hh.exe) spawning suspicious child processes such as command interpreters (cmd.exe, powershell.exe) or scripting engines (mshta.exe, wscript.exe). This behavior is characteristic of initial access techniques used by the Kimsuky (APT43) threat group, where malicious CHM files are delivered via email attachments to execute payloads.
Detects command-line activity indicative of DNS tunneling, often used by OilRig (APT34) for C2 communication via BONDUPDATER. The rule monitors PowerShell or nslookup commands executing DNS TXT record queries paired with long, base64-encoded subdomains, a technique used for exfiltrating data or receiving commands.
Detects DLL side-loading where a known legitimate signed executable, often associated with security utilities, loads a DLL from a non-standard, user-writable directory (such as Temp, AppData, or ProgramData). This behavior is characteristic of APT10's (Stone Panda/Cicada) historical tradecraft in MSP environments to execute modular PlugX RAT payloads.
Detects lateral movement via PsExec (PSEXESVC) followed by mass file encryption/rename activities and the creation of ransom note files, characteristic of Wizard Spider's deployment of Conti ransomware.
Page 87 of 1870


