Browse detections

Search across every tracked source. Filter by severity, format, or ATT&CK technique.

Reset

60775 matches · 19110 atomic-IOC hidden · show · 1802 non-detections hidden · show · 11698 deprecated hidden · include

Detection Source Severity ATT&CK Updated ↓
Anthropic Admin Role Assigned to User elastic/detection-rules High T1098 T1098.003 2026-10-07
Anthropic Primary Owner Transferred elastic/detection-rules High T1098 T1098.003 2026-10-07
AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox elastic/detection-rules High T1078 T1078.004 +1 2026-10-07
Connection to WebService by a Signed Binary Proxy elastic/protections-artifacts Undefined T1218 T1071 +2 2026-10-07
Creation of Hidden Shared Object File elastic/protections-artifacts Undefined T1129 T1564 +1 2026-10-07
DNS Request by Recently Created Executable elastic/protections-artifacts Undefined T1204 T1204.002 +3 2026-10-07
ET EXPLOIT Sunhillo SureLine Unauthenticated OS Command Injection Inbound (CVE-2021-36380) Emerging Threats Open High T1210 2026-10-07
ET HUNTING Javascript Redirect to Google .com Emerging Threats Open Informational 2026-10-07
GCP Vertex AI Caller Impossible Travel elastic/detection-rules Medium T1528 T1078 +1 2026-10-07
GCP Vertex AI High Request and Token Volume elastic/detection-rules Medium T1496 2026-10-07
Hidden Payload Executed via Scheduled Job elastic/protections-artifacts Undefined T1053 T1053.003 +2 2026-10-07
Ingress Tool Transfer via CURL elastic/protections-artifacts Undefined T1105 2026-10-07
Long Base64 Command Execution via Interactive Shell elastic/protections-artifacts Undefined T1059 T1059.001 +6 2026-10-07
Microsoft Windows Defender Tampering elastic/detection-rules Medium T1112 T1562 +1 2026-10-07
Non-interactive Shell Upgrade elastic/protections-artifacts Undefined T1059 T1059.004 2026-10-07
Potential Remote Code Execution via URL Encoded Payload elastic/protections-artifacts Undefined T1059 T1059.004 +5 2026-10-07
Potential Reverse Shell Activity via TCP/UDP Socket elastic/protections-artifacts Undefined T1059 T1059.004 +1 2026-10-07
Potential Reverse Shell Activity via Terminal elastic/protections-artifacts Undefined T1059 T1071 2026-10-07
Potential SUID/SGID Files Enumeration elastic/protections-artifacts Undefined T1548 T1548.001 +1 2026-10-07
Socat Reverse Shell or Listener Activity elastic/protections-artifacts Undefined T1059 T1059.004 +1 2026-10-07
Suspicious Echo Execution elastic/protections-artifacts Undefined T1053 T1053.003 +8 2026-10-07
Suspicious Enumeration via LDAP Search elastic/protections-artifacts Undefined T1069 T1069.002 +3 2026-10-07
Suspicious File Downloaded by Curl/Wget and Piped to Interpreter elastic/protections-artifacts Undefined T1059 T1059.004 +1 2026-10-07
Suspicious PowerShell Execution elastic/protections-artifacts Undefined T1059 T1059.001 2026-10-07
Suspicious Remote Javascript Evaluation via Nodejs elastic/protections-artifacts Undefined T1059 T1059.007 2026-10-07
Suspicious Ruby Command Execution elastic/protections-artifacts Undefined T1059 2026-10-07
System Reconnaissance from Unsigned Parent Followed by Network Connection elastic/protections-artifacts Undefined T1082 T1071 +1 2026-10-07
Unusual Command Execution via Cron elastic/protections-artifacts Undefined T1059 T1059.004 +4 2026-10-07
Unusual Command Execution via Systemd Scheduled Task elastic/protections-artifacts Undefined T1059 T1059.004 +4 2026-10-07
Access to a Sensitive LDAP Attribute elastic/detection-rules Medium T1003 T1552 +5 2026-10-06
AdFind Command Activity elastic/detection-rules Low T1016 T1018 +5 2026-10-06
AWS Bedrock Foundation Model Access Enabled or Entitlement Granted elastic/detection-rules Medium T1098 2026-10-06
AWS Bedrock Foundation Model Enumeration Followed by Invocation via Long-Term Key elastic/detection-rules High T1526 T1078 +1 2026-10-06
AWS Bedrock Unauthorized Foundation Model Access Attempt elastic/detection-rules Low T1098 2026-10-06
AWS EC2 Instance Console Login via Assumed Role elastic/detection-rules High T1021 T1021.007 +6 2026-10-06
AWS IAM CompromisedKeyQuarantine Policy Attached to User elastic/detection-rules High T1552 T1078 +1 2026-10-06
AWS S3 Bucket Replicated to Another Account elastic/detection-rules High T1537 T1567 +1 2026-10-06
AWS S3 Object Encryption Using External KMS Key elastic/detection-rules Medium T1486 2026-10-06
AWS S3 Object Versioning Suspended elastic/detection-rules Medium T1490 2026-10-06
AWS Suspicious User Agent Fingerprint elastic/detection-rules High T1078 T1078.004 2026-10-06
Azure OpenAI Insecure Output Handling elastic/detection-rules Low 2026-10-06
Cobalt Strike Command and Control Beacon elastic/detection-rules High T1071 T1071.001 +2 2026-10-06
Command Execution via SolarWinds Process elastic/detection-rules Medium T1059 T1059.001 +3 2026-10-06
Entra ID Conditional Access Policy (CAP) Modified elastic/detection-rules High T1556 T1556.009 2026-10-06
ET EXPLOIT eMerge E3 card_scan.php ReaderNo Parameter Command Injection Inbound (CVE-2019-7256) Emerging Threats Open High T1190 2026-10-06
ET EXPLOIT EnGenius EnShare IoT Gigabit Cloud Service usbinteract.gi path parameter Command Injection Attempt (CVE-2025-34035) Emerging Threats Open High T1190 2026-10-06
ET EXPLOIT_KIT ClickFix Payload Response M1 Emerging Threats Open Medium T1189 2026-10-06
ET EXPLOIT_KIT ClickFix Payload Response M2 Emerging Threats Open High T1189 2026-10-06
ET EXPLOIT_KIT ClickFix Visitor Tracking Emerging Threats Open Medium T1189 2026-10-06
ET MALWARE ContEXE Stealer Data Exfiltration Attempt M1 Emerging Threats Open High T1005 2026-10-06

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.