Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
Platforms
1
Products / Services
1
MITRE Techniques
17,933
15,403
12,289
8,184
6,030
Detects DNS resolutions to popular threat intelligence, reputation, and sandboxing APIs (e.g., VirusTotal, URLScan, AbuseIPDB) originating from non-browser processes on non-analyst workstations. This behavior may indicate an attacker programmatically querying these services to verify if their infrastructure, payloads, or IP addresses are flagged as malicious, or to conduct reconnaissance.
