Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,719 detections
Filters
Last updated
All Time
Detection languages
14,958
13,681
2,584
1,830
1,753
Contributors
7,678
6,007
5,304
4,504
3,924
Categories
17,809
9,464
3,730
3,649
3,647
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,086
9,489
6,964
1,880
1,704
MITRE Techniques
13,685
12,943
8,046
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to perform actions associated with ransomware, such as deleting volume shadow copies, deleting the backup catalog, or disabling system recovery features. This is a common precursor to data encryption to prevent the user from restoring files.
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) where a single user requests tickets for multiple distinct Service Principal Names (SPNs) using weak RC4 (0x17) encryption. This behavior is highly characteristic of Kerberoasting, a technique used by adversaries to harvest service account tickets for offline cracking.
Detects the abuse of signed Windows system binaries (LOLBins: certutil, mshta, regsvr32, rundll32, bitsadmin, msiexec) through the identification of command-line arguments that suggest malicious activity, such as downloading remote content, decoding files, executing scriptlets, or loading DLLs from temporary storage directories.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell. The rule looks for command-line arguments referencing AMSI-related memory structures, methods, and DLLs such as AmsiUtils, AmsiScanBuffer, AmsiInitFailed, and amsi.dll. Bypassing AMSI is a common technique used by attackers to execute malicious scripts and deploy fileless payloads, such as Cobalt Strike or Sliver, while avoiding detection by endpoint security solutions.
Detects potential Golden SAML activity by correlating Azure AD SAML sign-in events for privileged accounts with a lack of corresponding server-side ADFS authentication logs, unusual SAML issuer URIs, lack of on-premises authentication logs, or evidence of direct access to ADFS token-signing certificate private key material.
Detects the execution of native Windows utilities such as vssadmin, wmic, wbadmin, and bcdedit used to delete volume shadow copies, the backup catalog, or disable system recovery boot policies. This activity is a common precursor to ransomware encryption to prevent data restoration.
Detects the use of token manipulation APIs (DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser), the 'runas' command for credential switching, or the execution of known security token manipulation tools (e.g., incognito, Tokenvator, Invoke-TokenManipulation). This activity is commonly associated with privilege escalation and token theft.
Detects the use of data archival utilities (7zip, WinRAR) or command-line cloud synchronization tools (Rclone) to stage files in common temporary directories, immediately followed by network connections to known cloud storage endpoints. This pattern is characteristic of pre-encryption exfiltration activities often seen in ransomware campaigns.
Detects legitimate, signed executables from trusted system locations (e.g., System32) loading DLLs from non-standard, user-writable directories (e.g., Temp, AppData). This activity is a classic indicator of DLL side-loading, where an adversary places a malicious DLL in a directory to be picked up by a legitimate application, enabling the execution of malicious code under the context of a trusted process.
Detects suspicious cross-process memory operations where a source process requests process creation/write permissions on a target process (e.g., browsers, explorer.exe, or svchost.exe), followed immediately by the execution of a remote thread injection technique such as CreateRemoteThread, QueueUserAPC, or NtCreateThreadEx within the same process pair.
Detects multiple attempts to connect to administrative shares (ADMIN$, C$, IPC$) from a single source within a 60-second window. This pattern is indicative of automated lateral movement or enumeration attempts using the SMB protocol.
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
Detects the use of the built-in Windows utility rundll32.exe to execute the MiniDump functionality within comsvcs.dll against the Local Security Authority Subsystem Service (LSASS). This technique is a common method for attackers to bypass signature-based security tools and obtain sensitive credentials from memory.
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
Detects the abuse of the legitimate Windows system binaries regsvr32.exe and rundll32.exe to execute remote scripts or scriptlets, a technique often used to bypass application control and proxy execution of malicious code (similar to Squiblydoo).
Detects the execution of reg.exe with the 'save' command to extract the SAM, SYSTEM, or SECURITY registry hives to disk. This technique is commonly used by attackers to offline extract credential hashes, facilitating pass-the-hash attacks and lateral movement.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
Detects the execution of PowerShell with encoded commands (e.g., -EncodedCommand or -enc) combined with common download cradle indicators such as IEX, Net.WebClient, or DownloadString. This combination is highly indicative of fileless malware execution, initial access payload staging, or defense evasion techniques often employed by threat actors to bypass command-line monitoring.
Detects unauthorized directory replication requests (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) made against Active Directory by a user or computer account that is not a domain controller. This behavior is indicative of a DCSync attack, typically performed by tools like Mimikatz to extract password hashes for all domain accounts.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the task is configured to run in the security context of the SYSTEM account or executes suspicious binaries like PowerShell, mshta, or other living-off-the-land binaries. This behavior is indicative of potential persistence mechanisms employed by adversaries.
Detects the abuse of the built-in Windows utility 'certutil.exe' to download remote files using URL cache functionality or to deobfuscate base64-encoded payloads. This is a common LOLBin (Living-off-the-Land Binary) technique used in phishing loaders, malware delivery, and post-exploitation toolkits.


