Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects network indicators associated with the Exvicy/ErrTraffic 'ClickFix' campaign. The rule identifies the retrieval of malicious HTML lure templates from compromised WordPress sites and subsequent telemetry/registration calls to an attacker-controlled 'api.php' script, which are precursors to the fake Cloudflare Turnstile 'Win+R' execution sequence.
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
Detects instances of mshta.exe initiating network connections to cloud storage providers (CloudFront, Cloudflare R2/pages) to retrieve multiple remote files (specifically .js or .txt). This behavior is indicative of an exploit stage where mshta.exe is used as a LOLBAS to fetch orchestrator scripts and gadget payloads for memory-based deserialization attacks.
This rule detects potential HTML smuggling activity by identifying a browser process writing an executable file named 'config.exe' to the user's Downloads folder without a traditional network download event, followed immediately by Microsoft Defender SmartScreen or Antivirus reporting a warning or scan failure on the file. This behavior is indicative of a payload being reconstructed on the client-side via JavaScript blobs or data URLs, which is a common characteristic of HTML smuggling delivery chains.
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
This rule detects potential HTML smuggling activity by identifying a browser process writing an executable file named 'config.exe' to the user's Downloads folder without a traditional network download event, followed immediately by Microsoft Defender SmartScreen or Antivirus reporting a warning or scan failure on the file. This behavior is indicative of a payload being reconstructed on the client-side via JavaScript blobs or data URLs, which is a common characteristic of HTML smuggling delivery chains.
Detects UAT-11587 Stage 1 HTA and WSF stager template: hidden/zero-sized window, fixed Cloudflare Pages tracking beacon with ?track, and WinHttp/MSXML ActiveXObject loading Stage 2 from Cloudflare R2 or CloudFront.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
Detects SQL injection exploitation attempts against MOVEit Transfer targeting the CVE-2023-34362 vulnerability, followed by the deployment and subsequent interaction with the 'human2.aspx' webshell associated with Cl0p ransomware mass-exploitation campaigns.
Page 88 of 1870


