Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,719 detections
Filters
Last updated
All Time
Detection languages
14,958
13,681
2,584
1,830
1,753
Contributors
7,678
6,007
5,304
4,504
3,924
Categories
17,809
9,464
3,730
3,649
3,647
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,086
9,489
6,964
1,880
1,704
MITRE Techniques
13,685
12,943
8,046
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects unauthorized access by a non-browser process to Chromium-based 'Cookies' SQLite database files, which are used by browsers like Chrome, Edge, and Brave. This behavior is a strong indicator of credential theft or session hijacking, as attackers target these files to extract session cookies and bypass MFA for cloud services.
Detects unauthorized access attempts to Chromium-based browser credential storage files, specifically 'Login Data' (SQLite database) and 'Local State' (master key storage), by processes other than standard browsers or known security products. This activity is a common indicator of credential harvesting by information stealers such as LummaC2, Vidar, and RedLine.
Detects interactive (Logon Type 10) or network (Logon Type 3) authentication to Windows hosts originating from external, non-RFC1918 IP addresses using 'Negotiate' authentication. This pattern is indicative of potential lateral movement from a cloud-connected environment into on-premises infrastructure, specifically where an adversary might be leveraging stolen session artifacts or credentials to bypass standard Kerberos-based domain authentication.
This rule detects typical behavior associated with infostealers targeting browser data, specifically the creation of compressed archives (.zip, .rar) in temporary directories (Temp or AppData) and the subsequent exfiltration of data via known webhook services (e.g., Discord, Telegram, Pastebin) or direct IP connections. It filters out common signed backup and synchronization software to minimize noise.
Detects the ClickFix/fake-CAPTCHA initial access pattern where users are socially engineered into copying and pasting malicious commands into the Windows Run dialog or a browser-spawned shell. The rule matches on process creation events involving mshta.exe, powershell.exe, or wscript.exe initiated by explorer.exe or common shell-related processes, filtering out known administrative and deployment software.
Detects the use of administrative utilities (psexec.exe, wmic.exe, powershell.exe, cmd.exe) initiating network connections over common remote management ports (135, 139, 445, 3389, 5985, 5986) to internal destinations. This behavior is indicative of lateral movement activity, particularly when initiated from a host that has recently engaged in credential harvesting or infostealer-related activity. The rule excludes common, expected sources to minimize noise.
Detects activity indicative of the 'ClickFix' social engineering technique, where users are tricked into manually executing obfuscated commands (often from fake CAPTCHA or error prompts) via the Windows Run dialog or command-line interfaces. The rule correlates suspicious process execution (e.g., mshta, powershell, certutil, curl) originating from explorer.exe with the detection of common encoded/obfuscated command line patterns, or interactions with the Windows RunMRU registry key, which logs commands typed into the Run dialog.
Detects a multi-stage activity chain indicative of infostealer malware, including reading the browser 'Local State' file (containing the master key), accessing a browser process (likely for memory dumping or token extraction), and initiating an immediate outbound network connection to an external destination.
Detects unauthorized access to common browser credential storage files (Login Data, Cookies, Web Data, Local State) by processes other than standard web browsers. This rule identifies potentially malicious activity by filtering for rare or unsigned binaries executing from common staging directories (Temp, Downloads) or accessing browser files shortly after the process launch, which is a common behavior pattern for info-stealer malware.
Detects attempts to enumerate or access Windows Credential Manager and vault files, often used by adversaries to extract cached credentials. The rule monitors for execution of vaultcmd.exe, invocation of keymgr.dll via rundll32.exe, and unauthorized access to credential storage paths in AppData by non-system processes.
Detects processes that access multiple categories of sensitive data (browser autofill, cryptocurrency wallets, password manager exports, or system fingerprinting files) within a short time window. This behavior is highly indicative of modular infostealers or data-collection malware conducting 'stacking access' to stage sensitive information for exfiltration.
This rule detects network connections initiated by unsigned executables that were recently created (within one hour) in common staging directories such as AppData, Temp, or ProgramData. It specifically targets beacons to the Telegram Bot API or Discord webhooks, which are common patterns for command-and-control (C2) communication used by malware such as the Amadey bot.
Detects potential lateral movement by users who have recently been flagged for credential theft or infostealer activity. The rule correlates initial security alerts with subsequent Windows logon events (RDP, network/WinRM) or SMB share access, identifying users connecting to multiple distinct destinations within a 48-hour window.
Detects a hybrid identity attack sequence where an anomalous or high-risk cloud sign-in (e.g., AD FS, Azure AD Connect) is followed within 24 hours by suspicious on-premise Active Directory activity, specifically DCSync replication requests or Kerberoasting (high volume of TGS requests). This pattern is indicative of an attacker leveraging stolen cloud session tokens to pivot into on-premise infrastructure.
Detects the mounting of VHDX files via disk imaging tools or PowerShell, followed shortly (within 15 minutes) by the execution of a shell process with hidden window flags. This behavioral pattern is associated with the delivery of malicious payloads, such as those observed in Star Blizzard's RedFlick delivery chain for CosmicPulse.
Detects the creation of specific decoy scheduled tasks ('Internet Quality Test Connection', 'Network Configuration Manager', 'System Health Monitor') identified as part of the Star Blizzard actor's CosmicPulse delivery mechanism. The rule monitors for the creation of these tasks via schtasks.exe or system events, specifically when the task configuration references execution via rundll32.exe, regsvr32.exe, control.exe, or remote/UNC-based payloads.
Detects the execution of a Control Panel (.cpl) item using control.exe or rundll32.exe. The rule specifically looks for CPL files that were recently written to suspicious directories (Temp, AppData, Downloads) and correlates this execution with subsequent suspicious behaviors, such as spawning Python processes, outbound network connections, or registry modifications consistent with key storage or payload persistence.
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
Detects the execution of 'setup.js' by the node.js runtime when initiated by 'npm install' or 'postinstall' hooks. This behavior is a common indicator of a malicious supply chain attack where a compromised or malicious npm package executes unauthorized code during the package installation or setup phase.



