Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,719 detections
Filters
Last updated
All Time
Detection languages
14,958
13,681
2,584
1,830
1,753
Contributors
7,678
6,007
5,304
4,504
3,924
Categories
17,809
9,464
3,730
3,649
3,647
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,086
9,489
6,964
1,880
1,704
MITRE Techniques
13,685
12,943
8,046
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects scenarios where a node-based package manager (npm or npx) executes an 'install' command, which is immediately followed by the spawning of unexpected child processes such as interpreters (python, powershell, cmd, wscript, cscript, mshta) or network tools (curl). This behavior is characteristic of malicious npm packages used in supply chain attacks to deliver secondary payloads like BeaverTail, InvisibleFerret, or similar threats.
Detects reconnaissance and situational-awareness collection commands (e.g., tasklist, systeminfo, wmic, powershell) executed by processes matching suspected persistence artifacts associated with known malicious activity (specifically referencing potential Telegram C2 tasking). The rule monitors common discovery utilities spawned by suspicious process names or paths.
This rule detects the creation of a file within the SysWOW64 directory followed by an immediate modification or creation of a Windows Run registry key within a 10-minute window. This behavior is indicative of a persistence mechanism where a malicious file is dropped to a system directory and registered for execution at system startup or user logon.
Detects a coordinated malicious installation chain involving the creation of specific mutexes, establishment of persistence via Windows Registry Run keys, and subsequent tampering with Microsoft Defender exclusions using PowerShell. This sequence is indicative of the CHOSEN BRICK malware installation process.
Detects execution of the CHOSEN BRICK implant (process names smdqservice.exe or winappx.exe) initiating a network connection to Telegram infrastructure (C2) followed by a network connection to a cloud object-storage provider (vultrobjects.com, storjshare.io, or backblazeb2.com) for data exfiltration within a 30-minute window.
Detects instances where a non-browser process initiates network connections to multiple AI service providers and Discord within a 15-minute correlation window, potentially indicating automated data exfiltration or unauthorized interaction with AI platforms using tools other than standard web browsers.
Detects instances where a non-browser process initiates network connections to multiple AI service providers and Discord within a 15-minute correlation window, potentially indicating automated data exfiltration or unauthorized interaction with AI platforms using tools other than standard web browsers.
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
Detects unauthorized processes attempting to access the cloud instance metadata service (169.254.169.254). Adversaries frequently target this endpoint to extract sensitive instance information, such as IAM credentials or configuration data, typically as part of post-exploitation discovery or SSRF-based attacks.
Detects instances where AI agent host processes (such as Python, .NET, or IIS worker processes) spawn suspicious child processes like command interpreters or common system utilities. This behavior is indicative of potential Remote Code Execution (RCE) via prompt injection, where an AI agent is manipulated into executing arbitrary system commands.
Detects the suspicious retrieval and immediate execution of Agentic AI configuration files (e.g., AGENTS.md, KNOWLEDGE.md) from remote sources using common command-line utilities. This pattern is indicative of an adversary injecting malicious agent instructions or unauthorized configurations into an AI environment.
Detects incoming web requests containing a 'pagename' parameter with URL-encoded path traversal sequences, which could allow unauthorized file access or directory traversal attacks against WordPress page-template resolution as described in CVE-2026-87902.
This rule detects unauthorized attempts to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. It monitors for common post-exploitation tools (such as procdump, mimikatz, nanodump, and sqldumper) or built-in Windows techniques (using rundll32.exe with comsvcs.dll) that are typically used to extract sensitive credential material from process memory.
Detects the WMI provider host (wmiprvse.exe) spawning common living-off-the-land binaries often associated with command execution or lateral movement.
Detects anomalous patterns of Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting attacks. The rule identifies accounts requesting a high volume of service tickets for distinct Service Principal Names (SPNs), excluding the krbtgt account.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.



