Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,719 detections
Filters
Last updated
All Time
Detection languages
14,958
13,681
2,584
1,830
1,753
Contributors
7,678
6,007
5,304
4,504
3,924
Categories
17,809
9,464
3,730
3,649
3,647
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,086
9,489
6,964
1,880
1,704
MITRE Techniques
13,685
12,943
8,046
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
Detects instances where node, npm, or bun package installation processes modify the Claude AI settings.json file. This could indicate potential supply chain compromise or unauthorized configuration changes to the Claude application environment via malicious packages or scripts.
Detects PEEP Secure Preferences integrity-hash forgery (protection.macs/super_mac) and known PEEP persistence scripts (patch_secure_prefs.ps1, install_silent.ps1, force_enable.ps1), anchored to actual Chrome/Edge profile paths rather than generic terms like 'protection' or 'developer_mode' that appear in unrelated admin tooling.
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
Detects outbound network connections to 'registry.npmjs.org' originating from 'node' or 'bun' processes. This behavior may indicate an attempt to exfiltrate data, interact with malicious packages, or perform credential harvesting via npm tokens during execution.
Detects outbound network connections to 'registry.npmjs.org' originating from 'node' or 'bun' processes. This behavior may indicate an attempt to exfiltrate data, interact with malicious packages, or perform credential harvesting via npm tokens during execution.
This rule identifies potential command-and-control (C2) beaconing behavior by detecting repetitive, consistent connections (low jitter) to public IP addresses over common TLS ports (443, 8443, 4443, 9443) from processes that do not have a known history of connecting to those destinations. It establishes a baseline of historical connections to filter out legitimate traffic and uses a statistical analysis of connection intervals to highlight suspicious, non-human-like automated communication patterns.
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
This rule detects potential Command and Control (C2) beaconing activity by identifying periodic outbound network connections from suspicious or non-browser processes. It analyzes the time deltas between successful network connections; if the standard deviation of these intervals is low (indicating consistent timing) and a sufficient number of connections occur, it flags the behavior as a potential C2 heartbeat.
Detects suspicious DLL loads or file drops performed by security product processes (avp.exe, MsMpEng.exe) from directories outside of standard, trusted vendor paths. It specifically flags unsigned or invalidly signed DLLs, which is indicative of DLL sideloading techniques used to abuse security software workflows for potential privilege escalation.
Detects the execution of command-line shells (cmd, powershell, pwsh) running under the SYSTEM context that were initiated by or associated with a process containing 'ShieldBreak' in its filename. This behavior is indicative of a suspicious or potentially malicious process (e.g., a security bypass tool) attempting to spawn elevated shells.
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.



