Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
The following analytic detects when a unprivileged user changes an Admin accounts password. This is a common artifact of successful exploitation of the BlueHammer Windows Defender privilege escalation. The attacker's process momentarily changes the passwords of high-value local accounts including the built-in Administrator to spawn an authenticated shell session, then immediately reverts the passwords to avoid detection. This uses EventID 4723 to log this activity.
Detects the usage of command-line flags in AI coding assistant CLIs (such as Claude Code, Amazon Q CLI, and others) that intentionally skip security permissions, bypass approvals, or disable sandbox protections. The rule identifies potential developer activity that may inadvertently reduce the security posture of the development environment.
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
Detects the use of msxsl.exe or wmic.exe to process .xsl or .xslt files, potentially indicating the execution of embedded scripts. The rule calculates a risk score based on the combination of the utility name, the presence of an XSL/XSLT file reference in the command line, usage of suspicious file paths (e.g., Temp, AppData), and being launched by potentially suspicious parent processes like cmd.exe or powershell.exe.
This rule detects suspicious activity related to input capturing, keylogging, or credential access, specifically looking for corresponding 'ActionType' events in Microsoft Defender for Endpoint (DeviceEvents) logs. It alerts on processes performing these actions on devices.
This rule monitors endpoint telemetry for indicators of compromise (IOCs) associated with known malicious activity. It checks for file creation, process execution, and network connections that match a defined list of malicious file hashes (SHA256, SHA1, MD5), C2 IP addresses, and malicious domains or URL patterns.
Detects a process other than XBootMgr.exe spawned by XBootMgrSleep.exe.
XBootMgrSleep.exe is a Microsoft-signed Windows Performance Toolkit binary that can execute an arbitrary executable after a delay.
XBootMgrSleep.exe is a Microsoft-signed Windows Performance Toolkit binary that can execute an arbitrary executable after a delay.
This rule monitors for known malicious file hashes, command and control (C2) domains, and specific download URLs associated with identified threats. It correlates these indicators across process execution, file activity, and network connection logs to identify potential compromises or malicious activity related to the aware-cr1 infrastructure.
Detects the use of system utilities (wevtutil, PowerShell, wmic, etc.) or log-reading tools (grep, tail) for log enumeration or export when executed by processes that are not standard management or monitoring agents. This pattern is commonly associated with adversary efforts to gain situational awareness or identify security logs.
This rule detects processes invoking sensitive Windows API functions related to token manipulation (such as DuplicateToken, ImpersonateLoggedOnUser, or CreateProcessAsUser) when initiated by suspicious parent processes like PowerShell, CMD, or WScript. It uses a scoring system that increases risk if the execution occurs from common non-standard directories (e.g., Temp, Public) or is associated with non-system account contexts.
Detects the usage of command-line flags in AI coding assistant CLIs (such as Claude Code, Amazon Q CLI, and others) that intentionally skip security permissions, bypass approvals, or disable sandbox protections. The rule identifies potential developer activity that may inadvertently reduce the security posture of the development environment.
Detects anomalous process execution and loopback network activity associated with the Model Context Protocol (MCP) 'exec_in_session' method. This pattern indicates an adversary potentially abusing the AI coding assistant's MCP server capabilities to execute arbitrary commands as a C2 channel.
Detects obfuscated PowerShell scripts that enumerate Microsoft.PowerShell.Utility exported commands
and invoke cmdlets indirectly by array index. This can be used to evade detections
that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.
and invoke cmdlets indirectly by array index. This can be used to evade detections
that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Detects a suspected ClickFix social engineering attack where a user is tricked into pasting malicious commands into Windows Terminal, leading to a PowerShell download, followed by the appearance of specific known malicious artifacts (LockScreenContentServer.exe, dui70.dll, or 1.bat) within 15 minutes on the same device.
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
This rule detects network communication, DNS queries, email interactions, and URL clicks associated with known TA419 threat actor infrastructure. It monitors multiple telemetry sources to identify indicators of compromise (IOCs) such as specific domains, IP addresses, and email addresses.
This rule monitors for potentially malicious use of Windows Subsystem for Linux (WSL) binaries. It detects the execution of common command-line tools for reconnaissance, download, or lateral movement within the WSL environment, identifies the use of WSL to execute Windows 'living-off-the-land' binaries (Lolbins), and flags the installation of WSL components.
Detects the creation or modification of Python configuration files (.pth, sitecustomize.py, usercustomize.py) within site-packages or dist-packages directories when not initiated by recognized Python package managers. Such files can be abused to achieve arbitrary code execution upon Python interpreter startup, a common method for persistence or local privilege escalation in Python environments.
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
Page 1 of 1866




