Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
104
Detects PowerShell command execution that combines typical Active Directory or system reconnaissance commands with potential persistence mechanisms, which is a common indicator of post-exploitation activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
003
Detects DLLs potentially associated with the 'Lorem Ipsum Loader' malware family. These DLLs are designed to sideload into legitimate applications and contain embedded shellcode that is encoded as a sequence of English words to bypass entropy-based detection. The rule looks for the presence of the word-encoded blob alongside specific filenames commonly used in this sideloading technique.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
003
Detects the establishment of persistence on a Windows host by monitoring both Registry Run/RunOnce key modifications and Scheduled Task creation. The rule specifically looks for command lines or registry values that reference common Windows binary names (e.g., Microsoft Edge/Teams update helpers, LockScreenContentServer) which are frequently used by adversaries for masquerading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
003
Detects instances where the IIS worker process (w3wp.exe) spawns the Windows command shell (cmd.exe) to execute common reconnaissance commands such as whoami, hostname, systeminfo, and net user. This behavior is strongly indicative of post-exploitation activity following a successful web shell deployment on a web server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
003
Detects ClickFix-style attacks where a user is tricked into copying and pasting malicious, often obfuscated, commands into the Windows Run dialog or a command prompt. The detection identifies suspicious parent processes (like explorer.exe) spawning shell interpreters (powershell.exe, cmd.exe, mshta.exe) with inline encoded payloads or remote content retrieval patterns. It correlates these process executions with recent entries in the Windows RunMRU registry key to identify commands triggered via the Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
404
Detects the execution of MSP360 or generic RMM-labeled binaries originating from common user download directories (Downloads or Temp folders) when the filename mimics common phishing lures such as invoice, e-card, RSVP, or document-related naming conventions. This activity indicates a potential social engineering attempt to execute remote monitoring and management tools.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
104
This rule monitors endpoint telemetry (DNS queries, network connections, file creation, and process execution) to identify matches against a predefined list of known malicious indicators, including IP addresses, domains, and file hashes (SHA256). The rule differentiates between confirmed malicious activity and low-confidence indicators, providing a prioritized view of potential threats.
avatar
Arnold Chan@slaz
avatar
Hunters
22 hours ago
100
This rule monitors endpoint telemetry (DNS queries, network connections, file creation, and process execution) to identify matches against a predefined list of known malicious indicators, including IP addresses, domains, and file hashes (SHA256). The rule differentiates between confirmed malicious activity and low-confidence indicators, providing a prioritized view of potential threats.
avatar
Arnold Chan@slaz
Defender - KQL
22 hours ago
000
Detects file system activity indicative of Royal and BlackSuit ransomware, specifically monitoring for the creation of ransom notes like 'README.TXT' or 'README.BlackSuit.txt' and mass renaming/encryption of files using extensions associated with these families (.royal, .royal_u, .blacksuit).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
014
Detects suspicious behavior by the IIS worker process (w3wp.exe) indicative of web shell deployment, specifically the spawning of command interpreters (cmd.exe, powershell.exe) or the writing of .aspx files. This activity is consistent with exploitation campaigns targeting MOVEit Transfer, such as those conducted by the Lace Tempest (Cl0p) group.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
114
Detects the Akira ransomware binary staged as C:\storage\win.exe and identified by its known SHA256 hash
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 hours ago
000
Detects the Akira ransomware binary staged as C:\storage\win.exe and identified by its known SHA256 hash
avatar
Arnold Chan@slaz
avatar
Hunters
22 hours ago
000
Detects the GOST tunnel binary deployed as svchost.exe from a staging directory, identified by its known hash, or by an unsigned PE importing config.dll with a matching MZ header and embedded config.dll reference (reduces FPs from legitimately signed software that imports a DLL of the same name)
avatar
Arnold Chan@slaz
avatar
Hunters
22 hours ago
000
Detects the GOST tunnel binary deployed as svchost.exe from a staging directory, identified by its known hash, or by an unsigned PE importing config.dll with a matching MZ header and embedded config.dll reference (reduces FPs from legitimately signed software that imports a DLL of the same name)
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 hours ago
000
Detects the execution of PowerShell with a bypass execution policy that performs a download or web request to save content to a file in the user's temp directory, followed by the immediate execution of that file. This pattern is characteristic of multi-stage malware droppers or fileless attack techniques attempting to stage and execute malicious scripts from temporary locations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
406
This rule monitors DeviceProcessEvents for the execution of known malicious binaries associated with the SilverFox malware. It specifically looks for occurrences of three distinct SHA256 file hashes within the last 30 days.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
205
Detects SQL injection exploitation attempts against MOVEit Transfer targeting the CVE-2023-34362 vulnerability, followed by the deployment and subsequent interaction with the 'human2.aspx' webshell associated with Cl0p ransomware mass-exploitation campaigns.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
004
Detects modifications to registry keys associated with the 'ms-settings' protocol handler. Adversaries often abuse these keys to perform UAC bypass by injecting a command into the 'shell/open/command' registry path for auto-elevating Windows binaries like fodhelper.exe, eventvwr.exe, sdclt.exe, or ComputerDefaults.exe.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
10 days ago
607
This rule detects instances where wscript.exe spawns iexplore.exe. This behavior is highly suspicious because Microsoft Windows Script Host (wscript.exe) is typically used for running VBScript or JScript files, and it rarely requires launching Internet Explorer (iexplore.exe). Such execution chains are often used by malware or malicious scripts to bypass security controls or to execute code within the context of a browser process.
avatar
Luís Marques@remotecodeexecution
avatar
SIBS Cyberwatch
7 days ago
103
This rule detects network communication attempts to a specific set of domains associated with the AgtaBackup Remote Access Trojan (RAT). It monitors DeviceNetworkEvents for outbound connections directed toward known command-and-control (C2) infrastructure used by this threat actor.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
605
Page 10 of 1866