Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.
Detects the modification or creation of the registry key '.mollis' within Software\Classes, which is used by the Star Blizzard (RedFlick) CPL downloader to store an encrypted AES key. This activity is performed by common Windows processes such as control.exe, rundll32.exe, or regsvr32.exe.
Detects the modification or creation of the registry key '.mollis' within Software\Classes, which is used by the Star Blizzard (RedFlick) CPL downloader to store an encrypted AES key. This activity is performed by common Windows processes such as control.exe, rundll32.exe, or regsvr32.exe.
This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.
Detects a specific multi-stage infection chain associated with Star Blizzard. The sequence begins with a command shell launched under conhost.exe executing SSH with PermitLocalCommand enabled, followed by the execution of a control panel (.cpl) file via control.exe within a two-hour window.
Detects successful RDP (Remote Desktop Protocol) logon events (Event ID 4624, Logon Type 10) where the source IP address is outside the predefined internal network ranges. This behavior is indicative of potential lateral movement, where an attacker attempts to access internal systems from an external, non-corporate source.
Detects unauthorized processes requesting memory access to lsass.exe with read permissions commonly associated with credential dumping techniques like Mimikatz. It identifies remote handle requests to lsass.exe, which are frequently used by tools deployed via network services or remote execution methods to extract credentials from memory.
Detects the use of native Windows administration utilities (vssadmin, wbadmin, bcdedit, wmic) to delete volume shadow copies, backup catalogs, or disable system recovery configurations. The rule specifically monitors for patterns where these commands are executed across multiple hosts or in rapid succession by the same account, behavior frequently observed during the precursor stages of ransomware deployment, such as the ShinyHunters ShinySp1d3r campaign.
Detects the execution of TruffleHog, an automated secret-scanning CLI tool, often utilized by threat actors to harvest sensitive credentials from local filesystems, repositories, environment variables, or CI/CD configuration files following unauthorized access.
Detects the execution of the GigaWiper malware or the use of common system commands associated with destructive data activities, such as recursive file removal, disk formatting, or secure data overwriting, often used by threat actors for extortion.
Detects a burst of Kerberos TGS-REQ (Ticket-Granting Service Request) messages using RC4 encryption (etype 0x17) over UDP or TCP port 88. A high volume of these requests from a single source within a short timeframe is indicative of Kerberoasting, a technique where an attacker requests service tickets to perform offline password cracking of service account credentials.
Detects anomalous MS-DRSR DRSGetNCChanges requests occurring between hosts where the requester is not a recognized Domain Controller. This pattern is commonly used by attackers to perform a DCSync attack, allowing for the replication of sensitive Active Directory data such as user password hashes.
Detects anomalous network traffic patterns characteristic of the PetitPotam exploit, specifically targeting the MS-EFSRPC interface on Windows SMB pipes. This behavior is used to force a remote system to initiate authentication to a specified target, facilitating NTLM relay attacks.
Detects NTLM authentication attempts targeting administrative network shares (ADMIN$ or C$) over the SMB protocol. This behavior is a common indicator of lateral movement techniques such as Pass-the-Hash, where an adversary uses captured NTLM hashes to authenticate to remote systems.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Page 98 of 1870


