Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution of PowerShell with hidden window styles and encoded commands, initiated with High Integrity (Admin) privileges. This pattern is often indicative of bypasses for User Account Control (UAC) or malicious script execution where an adversary attempts to run elevated code while minimizing user visibility.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
005
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
103
Detects modifications to Group Policy Objects (GPOs) or GPO links in Active Directory, specifically targeting known malicious GPO identifiers, GPO payloads, or changes to policy versioning and linking that indicate unauthorized configuration changes for persistence or privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
405
Detects a cluster of Windows Event IDs 4740 (Account Lockout) or 4724 (Password Reset) targeting the local 'Administrator' account across multiple hosts within a short time window. This activity is indicative of automated or mass account manipulation often associated with ransomware payloads or centralized GPO-based credential tampering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
005
Detects a suspicious pattern across the environment where a large number of devices apply Group Policy Objects (GPO) shortly after rebooting. This behavior is indicative of potential unauthorized GPO modification used as a persistence or execution mechanism, where malicious logic is staged within a GPO to trigger across the domain upon machine startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
005
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects the execution of PowerShell via a shortcut (.lnk) file that attempts to download and execute remote content using 'Invoke-WebRequest'. The command lines use common obfuscation techniques like 'Hidden' window style and 'Bypass' execution policy, targeting specific known malicious URL patterns or filename keywords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
305
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
001
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
001
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
001
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
Detects the execution of PowerShell scripts located in Windows temporary directories (AppData/Local/Temp or Temp) that utilize common evasion flags such as hidden window style, bypass execution policy, or non-interactive mode. This behavior is frequently associated with initial stagers, droppers, or malicious script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
006
Detects the loading of specific DLL files (winfsp-x64.dll or DukeQt.dll) where the loading process or the DLL file location originates from outside the legitimate system directory (C:\Windows\). This behavior is often associated with DLL sideloading or search order hijacking where a malicious actor places a DLL in an untrusted directory to be loaded by a legitimate application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
005
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
103
Detects UNC6240 PSEMHUB.war web shell/tunnel/trojanized installer artifacts by distinctive content markers (x.jsp, u.jsp, tunnel.jsp/jspx, Ple64.exe)
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
001
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
001
Page 102 of 1870