Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
Detects the loading of the known vulnerable GIGABYTE driver (gdrv.sys) on Windows systems. Attackers leverage this driver as part of Bring Your Own Vulnerable Driver (BYOVD) attacks to perform privilege escalation by exploiting kernel-mode vulnerabilities.
Detects instances where a suspicious PowerShell, mshta, or pwsh command, typically involving download or obfuscation patterns, is launched as a child process of Windows Explorer within two minutes of a modification to the Explorer RunMRU registry key. This behavior is indicative of an adversary attempting to achieve execution, often following user interaction or persistence triggers.
Detects the ClickFix behavioral pattern where Windows Explorer (typically triggered via the Run dialog) directly spawns PowerShell.exe. This activity is indicative of a user being socially engineered into copying and executing a malicious command from a fake CAPTCHA lure directly into the shell.
This rule detects instances where the Faronics Deploy Agent process initiates the installation or download of ScreenConnect remote access software via PowerShell or the Windows Installer (msiexec.exe). This pattern is often indicative of authorized RMM deployment, but it is also a common tactic for adversaries to establish persistent remote access to endpoints.
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
This rule monitors for known malicious file hashes, command and control (C2) domains, and specific download URLs associated with identified threats. It correlates these indicators across process execution, file activity, and network connection logs to identify potential compromises or malicious activity related to the aware-cr1 infrastructure.
Detects a process querying multiple distinct registry keys associated with virtual environments (VMware, VirtualBox, Wine) in a short time window. This behavior is indicative of environmental profiling performed by malware (such as 2CLoader) to detect sandbox or analysis environments prior to malicious payload execution.
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
Detects potentially malicious use of rundll32.exe by monitoring for execution from suspicious directory paths (e.g., Temp, AppData, Downloads), execution with arguments missing common legitimate entry points, unexpected network connections originating from rundll32.exe, or rundll32.exe spawning child processes (excluding known safe binaries like conhost.exe or werfault.exe).
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
This rule identifies installations of TeamViewer software that are vulnerable to specific CVEs (CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371) by analyzing the 'DeviceTvmSoftwareInventory' dataset. It checks for versioning patterns against known vulnerable build numbers across Windows, Linux, and macOS platforms to pinpoint systems requiring patching.
This rule monitors for various indicators of compromise (IOCs) including malicious domains, IP addresses, specific URI paths, file names, and file hashes. It aggregates telemetry from network, file, process, and certificate events to detect potential threats interacting with known bad infrastructure or executing suspicious files associated with malware campaigns.
Detects a sequence of events where a user clicks a shared link to an AI chatbot conversation followed closely (within 15 minutes) by the execution of potentially malicious processes (mshta, powershell, cmd) that include suspicious command-line patterns indicative of ClickFix-style social engineering.
Detects a sequence of events where a user clicks a shared link to an AI chatbot conversation followed closely (within 15 minutes) by the execution of potentially malicious processes (mshta, powershell, cmd) that include suspicious command-line patterns indicative of ClickFix-style social engineering.
Detects a sequence of events where a user clicks a shared link to an AI chatbot conversation followed closely (within 15 minutes) by the execution of potentially malicious processes (mshta, powershell, cmd) that include suspicious command-line patterns indicative of ClickFix-style social engineering.
Page 9 of 1866


