Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,719 detections
Filters
Last updated
All Time
Detection languages
14,958
13,681
2,584
1,830
1,753
Contributors
7,678
6,007
5,304
4,504
3,924
Categories
17,809
9,464
3,730
3,649
3,647
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,086
9,489
6,964
1,880
1,704
MITRE Techniques
13,685
12,943
8,046
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects anomalous lateral movement behavior by monitoring Windows Event 4624 (Logon Type 3) using NTLM authentication. The rule triggers when a single user account authenticates to five or more distinct hosts within a five-minute window, a pattern frequently associated with Pass-the-Hash attacks where captured credentials are used to spread across a network.
Detects non-SYSTEM processes enabling SeDebugPrivilege or SeImpersonatePrivilege shortly before launching a process as the SYSTEM user. This behavior is highly indicative of token manipulation and impersonation techniques (e.g., Potato-family exploits) used to elevate privileges from a standard or administrative account to SYSTEM.
Detects attempts to disable security services (Windows Defender, EDR agents), modify audit policies via auditpol, or stop/clear the Windows Event Log service. This behavior is a common precursor to post-compromise activity intended to blind defenders and conceal malicious actions.
Detects an attempt to perform Active Directory replication (DS-Replication-Get-Changes or DS-Replication-Get-Changes-All) initiated by a machine that is not a recognized Domain Controller. This is a common indicator of credential dumping or unauthorized domain information gathering.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
This rule detects the creation of scheduled tasks using either 'schtasks.exe' or PowerShell ('powershell.exe', 'pwsh.exe') with suspicious parameters. It flags tasks created in temporary directories (e.g., AppData, Temp, ProgramData, Windows\Temp) or tasks executed with 'highest' privileges or hidden configurations, often used for persistence or lateral movement.
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
Detects attempts to dump credentials from the Local Security Authority Subsystem Service (LSASS) process memory using common tools like Mimikatz, Procdump, or built-in system utilities such as comsvcs.dll or command-line arguments indicating memory dump operations.
Detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos TGS requests (Event ID 4769) for tickets encrypted with RC4 (0x17) within a short timeframe. The rule tracks the count of requests and the diversity of Service Principal Names (SPNs) requested by a specific user account, excluding machine accounts.
Detects potential persistence mechanisms on Windows systems by monitoring for the creation or modification of Registry 'Run' or 'RunOnce' keys, as well as the creation of files within the Windows Startup folder. These actions are commonly used by adversaries to ensure malicious code executes automatically upon user login or system startup.
Detects execution of regsvr32.exe with command-line arguments that include a remote URL ('/i:http...') combined with silent, unregistered, and notification-free execution flags ('/s', '/u', '/n'). This behavior is characteristic of the 'Squiblydoo' technique, where attackers use Regsvr32 to execute arbitrary scriptlets from remote servers to bypass application whitelisting.
Detects instances of rundll32.exe being used with suspicious command line arguments, such as referencing JavaScript, loading Control Panel applets (.cpl) via shell32.dll from non-standard locations, or executing DLLs directly from user-writable directories (Temp, AppData, Downloads, ProgramData). These patterns are common techniques used by adversaries to proxy execution and evade detection.
Detects potential lateral movement and persistence activities by identifying suspicious Windows service installations via event ID 7045. The rule flags services with suspicious names or paths (e.g., Temp folders, Public directory) and correlates them with incoming SMB connections (port 445) or services spawned directly by services.exe from suspicious locations, aggregated by host and remote IP.
Detects the execution of the Microsoft HTML Application host (mshta.exe) when it is used to launch scripts from remote URLs (http/https/ftp) or when it spawns common command-line shells and scripting engines, which is a common indicator of living-off-the-land techniques used to execute malicious payloads.
This rule detects various forms of process injection (Remote Thread, APC, Map View of Section) targeting common, high-value Windows processes such as explorer.exe, lsass.exe, and web browsers. This behavior is a common technique used by attackers to gain persistence, elevate privileges, or execute code within the context of legitimate system or user-level processes to evade detection.
Detects unauthorized attempts by processes to access the memory of sensitive Windows system processes, specifically LSASS.exe or winlogon.exe, using suspicious access masks associated with memory dumping or credential harvesting.
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
Detects the abuse of signed Windows system binaries regsvr32.exe and rundll32.exe for proxy execution, defense evasion, and credential access. The rule identifies suspicious command-line patterns including Squiblydoo (regsvr32 with remote scriptlets), rundll32 executing JavaScript via mshtml.dll, rundll32 performing LSASS credential dumping via comsvcs.dll, and the loading of DLLs from untrusted user-writable locations like Temp or Downloads folders.
Detects Kerberos service ticket requests (EventID 4769) that utilize RC4 encryption (0x17) instead of the more secure AES encryption. Attackers often force RC4-HMAC when requesting service tickets for accounts with Service Principal Names (SPNs) because these tickets are susceptible to offline brute-force attacks to recover service account passwords. This technique is a common precursor to lateral movement and privilege escalation in Active Directory environments.

