Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects outbound network connections from internal devices to a set of known malicious IP addresses (217.156.122.129, 37.221.66.43) across commonly abused command-and-control ports (8080, 3480, 9998, 9999, 4444).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
22 days ago
7018
This rule detects activity involving known malicious indicators of compromise (IOCs), including specific IP addresses, domains, and file hashes. It monitors network connections, file system activity, process execution, and email attachments, filtering out common security tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects activity involving known malicious indicators of compromise (IOCs), including specific IP addresses, domains, and file hashes. It monitors network connections, file system activity, process execution, and email attachments, filtering out common security tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects activity involving known malicious indicators of compromise (IOCs), including specific IP addresses, domains, and file hashes. It monitors network connections, file system activity, process execution, and email attachments, filtering out common security tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects Bitsadmin connections to domains with uncommon TLDs
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
9 days ago
000
This rule detects potential persistence via scheduled tasks that masquerade as legitimate network components (e.g., 'System Health Monitor'), as well as abnormal use of WebDav via rundll32.exe or net.exe in the context of the Star Blizzard (COLDRIVER) campaign. It monitors for task creation/updates, schtasks command lines, registry artifacts related to task scheduling, and suspicious WebDav network utility usage, while excluding common security tool processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects potential persistence via scheduled tasks that masquerade as legitimate network components (e.g., 'System Health Monitor'), as well as abnormal use of WebDav via rundll32.exe or net.exe in the context of the Star Blizzard (COLDRIVER) campaign. It monitors for task creation/updates, schtasks command lines, registry artifacts related to task scheduling, and suspicious WebDav network utility usage, while excluding common security tool processes.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects execution of potentially malicious or dual-use tools (such as credential dumpers or security-bypass utilities) from within ScreenConnect temporary directories via the 'RunFile' command. This is indicative of an attacker leveraging legitimate remote support software to deploy secondary payloads.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects execution of potentially malicious or dual-use tools (such as credential dumpers or security-bypass utilities) from within ScreenConnect temporary directories via the 'RunFile' command. This is indicative of an attacker leveraging legitimate remote support software to deploy secondary payloads.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Page 103 of 1870