Detection Rule Index
An index of more than 3,700 community detection rules (Sigma, YARA), each linked to the ATT&CK techniques it covers and the malware it detects.
- WordPress Wp2shell REST Batch Endpoint Exploitation SIGMA · medium
- WordPress Wp2shell Webshell Plugin Access SIGMA · critical
- WordPress Wp2shell Exploitation Tool User-Agent SIGMA · high
- TanStack Supply-Chain Attack File Creation Indicators - Linux SIGMA · medium
- TanStack Supply-Chain Attack File Creation Indicators - Windows SIGMA · medium
- TanStack Supply-Chain Attack DNS Indicators SIGMA · medium
- TanStack Supply-Chain Attack Execution Indicators - Windows SIGMA · high
- TanStack Supply-Chain Attack Execution Indicators - Linux SIGMA · high
- AppLocker Application Would Have Been Blocked SIGMA · medium
- Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog SIGMA · medium
- AWS Bedrock Claude Unusually Large Prompts SPLUNK
- AWS Bedrock Claude High Risk Filesystem and Exec Tool Invocation SPLUNK
- AWS Bedrock Claude Hostile Prompt Sentiment SPLUNK
- AWS Bedrock Claude Cross Region Possible Inference Abuse SPLUNK
- AWS Bedrock Claude Possible Prompt Injection SPLUNK
- AWS Bedrock Claude Sensitive Data in Prompts SPLUNK
- AWS Bedrock Claude excessive use of tokens SPLUNK
- Windows Uncommon Remote Thread Creation In Browser Process SPLUNK
- Linux Dirty Frag Kernel Privilege Escalation SPLUNK
- Detect attackers scanning for vulnerable JBoss servers SPLUNK
- F5 TMUI Authentication Bypass SPLUNK
- Detect Web Access to Decommissioned S3 Bucket SPLUNK
- Citrix ShareFile Exploitation CVE-2023-24489 SPLUNK
- Confluence Data Center and Server Privilege Escalation SPLUNK
- Cisco IOS XE Implant Access SPLUNK
- Confluence CVE-2023-22515 Trigger Vulnerability SPLUNK
- Detect Remote Access Software Usage URL SPLUNK
- Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 SPLUNK
- Confluence Unauthenticated Remote Code Execution CVE-2022-26134 SPLUNK
- ConnectWise ScreenConnect Authentication Bypass SPLUNK
- Detect F5 TMUI RCE CVE-2020-5902 SPLUNK
- Citrix ADC Exploitation CVE-2023-3519 SPLUNK
- CrushFTP Max Simultaneous Users From IP SPLUNK
- Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082 SPLUNK
- Citrix ADC and Gateway Unauthorized Data Disclosure SPLUNK
- Windows Multi hop Proxy TOR Website Query SPLUNK
- CrushFTP Authentication Bypass Exploitation SPLUNK
- Windows Gather Victim Network Info Through Ip Check Web Services SPLUNK
- Suspicious Process With Discord DNS Query SPLUNK
- Detect malicious requests to exploit JBoss servers SPLUNK
- TOR Traffic SPLUNK
- SMB Traffic Spike SPLUNK
- Windows DNS Query Request by Telegram Bot API SPLUNK
- Windows Remote Desktop Network Bruteforce Attempt SPLUNK
- Zeek x509 Certificate with Punycode SPLUNK
- Adobe ColdFusion Unauthenticated Arbitrary File Read SPLUNK
- Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure SPLUNK
- Confluence Pre-Auth RCE via OGNL Injection CVE-2023-22527 SPLUNK
- Access to Vulnerable Ivanti Connect Secure Bookmark Endpoint SPLUNK
- Windows AD Replication Service Traffic SPLUNK