Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,719 detections
Filters
Last updated
All Time
Detection languages
14,958
13,681
2,584
1,830
1,753
Contributors
7,678
6,007
5,304
4,504
3,924
Categories
17,809
9,464
3,730
3,649
3,647
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,086
9,489
6,964
1,880
1,704
MITRE Techniques
13,685
12,943
8,046
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects the request for DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights on domain objects, which are highly sensitive Active Directory permissions required to perform DCSync attacks to harvest credentials from Domain Controllers.
Detects unauthorized modifications to Windows Registry Run/RunOnce keys or the Startup folder. The rule specifically targets persistence attempts where the associated process resides in suspicious directories (Temp, AppData) or uses command-line arguments indicative of script execution (powershell, wscript, mshta, encoded commands, or script extensions). It excludes known legitimate installer behavior involving msiexec or setup processes.
Detects WmiPrvSE.exe spawning child processes within 120 seconds of a Type 3 (Network) logon event. This behavior is a common indicator of remote command execution, frequently used by lateral movement tools like Impacket's wmiexec or similar WMI-based remote execution frameworks.
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests using the weak RC4 encryption type (0x17) from a single account within a 5-minute window. It excludes machine accounts and common system service requests to reduce noise.
This rule detects suspicious NTLM network logon events (Logon Type 3) involving privileged accounts that do not have corresponding Kerberos authentication events (4768/4769) in the preceding hour. The detection specifically triggers when a single account logs into two or more distinct hosts within a 15-minute window, which is indicative of lateral movement using compromised credentials or Pass-the-Hash techniques.
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
Detects the creation of scheduled tasks using Event ID 4698 or command-line execution of schtasks.exe. The rule specifically looks for tasks created in suspicious paths such as AppData or ProgramData, or tasks configured to run with highest privileges and/or marked as hidden, which are common indicators of persistence mechanisms used by adversaries.
Detects anomalous Kerberos service ticket (TGS) requests or successful logons where the corresponding Ticket Granting Ticket (TGT) request (Event ID 4768) is absent within the monitored window. This pattern is a primary indicator of offline-forged Kerberos tickets, such as those generated by Mimikatz, which bypass legitimate KDC interaction for ticket issuance.
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
Detects the creation of scheduled tasks using Event ID 4698 or command-line execution of schtasks.exe. The rule specifically looks for tasks created in suspicious paths such as AppData or ProgramData, or tasks configured to run with highest privileges and/or marked as hidden, which are common indicators of persistence mechanisms used by adversaries.
Detects anomalous Kerberos service ticket (TGS) requests or successful logons where the corresponding Ticket Granting Ticket (TGT) request (Event ID 4768) is absent within the monitored window. This pattern is a primary indicator of offline-forged Kerberos tickets, such as those generated by Mimikatz, which bypass legitimate KDC interaction for ticket issuance.
This rule detects the suspicious execution of rundll32.exe or regsvr32.exe, which are commonly abused as Living-off-the-Land Binaries (LOLBins). It identifies potential malicious activity by analyzing command-line arguments for patterns like remote URL requests, usage of scrobj.dll, JavaScript protocols, or specific Squiblydoo attack patterns. Additionally, it monitors for these binaries being executed by parents other than explorer.exe, which is indicative of potential process injection or proxy execution.
Detects attempts to access or dump the memory of the Local Security Authority Subsystem Service (LSASS) process, a technique commonly used by adversaries to harvest domain credentials and clear-text passwords from memory.
Detects lateral movement techniques leveraging Windows Management Instrumentation (WMI). The rule identifies instances where the WMI provider host, WmiPrvSE.exe, spawns common administrative or interactive shell tools (e.g., cmd.exe, powershell.exe). This pattern is consistent with the abuse of Win32_Process.Create() via WMI/DCOM/RPC for remote command execution, a method frequently utilized by frameworks like Impacket (wmiexec.py) for fileless, agentless lateral movement.
This rule detects potential RDP brute force and password spraying attacks by correlating Windows Event ID 4625 (failed logins) and 4624 (successful logins) via RDP (Logon Type 10). It monitors for high volumes of failed attempts across multiple accounts or high volume of failed attempts from a single source, followed by successful authentication from the same source.
Detects unauthorized usage of the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, which are required for the DCSync technique. The rule monitors for Windows Event ID 4662 (Object Access) where a non-domain controller account attempts these replication operations, typically indicative of credential dumping and domain compromise.
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (LSASS) process with access rights consistent with credential dumping (e.g., PROCESS_VM_READ, PROCESS_ALL_ACCESS). This rule also specifically flags the use of well-known tools and techniques such as Mimikatz, ProcDump, and the abuse of rundll32.exe with comsvcs.dll for memory extraction, which is indicative of OS Credential Dumping (T1003.001).
This rule detects persistence mechanisms by monitoring additions to Windows Registry Run keys or files created in the user's Startup directory. It specifically flags entries that target suspicious locations (e.g., Temp, AppData, Public) or attempt to execute encoded commands using PowerShell or CMD.
This rule detects potential lateral movement indicative of PsExec or similar administrative tools. It identifies the combination of remote service installation (often using ADMIN$ or Temp paths), access to administrative shares (ADMIN$ or C$), and the execution of a process spawned by services.exe, which is characteristic of the remote service control manager performing remote service starts.
This rule detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to perform actions associated with ransomware, such as deleting volume shadow copies, deleting the backup catalog, or disabling system recovery features. This is a common precursor to data encryption to prevent the user from restoring files.
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) where a single user requests tickets for multiple distinct Service Principal Names (SPNs) using weak RC4 (0x17) encryption. This behavior is highly characteristic of Kerberoasting, a technique used by adversaries to harvest service account tickets for offline cracking.
