Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the installation of machine learning or AI software dependencies (pip, conda, npm, poetry) that either pull from unauthorized registries or match known malicious/typosquatting naming patterns (e.g., LiteLLM supply-chain compromise). The rule also monitors for newly published packages that have been flagged as suspicious.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects an AI agent session that performs a data exfiltration action (e.g., sending an email, webhook, or file share) to an unauthorized or non-allowlisted destination shortly after the agent has ingested potentially untrusted external content. This behavior is indicative of an AI agent being manipulated to exfiltrate data after processing malicious or adversarial inputs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule monitors package installation logs for indicators of packages potentially generated or suggested by AI tools (e.g., Copilot, code assistants) being installed in a target environment. It specifically looks for a low volume of installations (<=3) for packages that have been published within the last 14 days, which is a pattern often associated with the 'Publish Hallucinated Entities' technique in AI systems, where malicious or hallucinated code packages are introduced into the supply chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects the execution of common Windows administration utilities (vssadmin.exe, wmic.exe, wbadmin.exe, bcdedit.exe) being used to delete Volume Shadow Copies, backup catalogs, or modify boot configuration data to disable automatic recovery. These actions are frequently performed by ransomware to prevent data restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where Microsoft Office applications or Windows Explorer (via LNK file execution) spawn suspicious child processes, such as script interpreters or known LOLBins, within a short timeframe. This is a common pattern for initial access via spearphishing attachments where a malicious document or shortcut executes a payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects high-volume file rename and modification operations occurring across multiple directories, combined with the creation of files indicative of ransom notes (e.g., readme, decrypt, how-to-restore). This pattern is strongly associated with the encryption phase of a ransomware attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the creation of scheduled tasks using schtasks.exe or PowerShell cmdlets that execute with SYSTEM privileges, or tasks that reference common temporary directories or persistence triggers (logon, idle). This behavior is frequently associated with ransomware, malware persistence, or staged payload execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of PowerShell with encoded command arguments (e.g., -enc, -EncodedCommand) combined with common web-request cmdlets or download-cradle patterns (e.g., IEX, Net.WebClient, Invoke-WebRequest). This pattern is frequently used by adversaries to execute obfuscated remote payloads in memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a suspicious burst of commands commonly used to disable security services, antivirus, or backup agents on a single host. The rule monitors for a high frequency of taskkill, net stop, sc stop, or PowerShell Stop-Service operations targeting a predefined list of sensitive security software process and service names within a short timeframe, which is a common precursor to ransomware encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects attempts by an adversary to disable or clear Windows Event logs using standard administrative utilities such as wevtutil, PowerShell, auditpol, net, sc, or wmic to cover tracks or hinder forensic analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects persistence attempts via Windows Registry run keys and Startup folders. The rule identifies suspicious modifications to run/runonce registry keys involving common user-writable paths (e.g., Temp, AppData) or the execution of PowerShell commands with common obfuscation flags (e.g., -enc). Additionally, it detects the creation of executable files (.lnk, .ps1, .vbs, .bat) within user Startup folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects persistence attempts via Windows Registry run keys and Startup folders. The rule identifies suspicious modifications to run/runonce registry keys involving common user-writable paths (e.g., Temp, AppData) or the execution of PowerShell commands with common obfuscation flags (e.g., -enc). Additionally, it detects the creation of executable files (.lnk, .ps1, .vbs, .bat) within user Startup folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects the deployment of suspicious executables or scripts (e.g., .exe, .bat, .ps1, .vbs) via Group Policy (GPO) paths or through GPO-related processes like gpscript.exe and gpupdate.exe. This activity is consistent with using GPOs to distribute and execute malicious binaries across a domain, often a precursor to ransomware deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the deletion of Windows Volume Shadow Copies using vssadmin.exe, wmic.exe, or PowerShell (WMI/CIM objects). This activity is commonly used by ransomware to prevent local data recovery by destroying shadow copy backups before encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the deletion of Windows Volume Shadow Copies using vssadmin.exe, wmic.exe, or PowerShell (WMI/CIM objects). This activity is commonly used by ransomware to prevent local data recovery by destroying shadow copy backups before encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects attempts to clear Windows Event Logs using either the native 'wevtutil.exe' utility or PowerShell cmdlets 'Clear-EventLog' and 'Remove-EventLog'. Adversaries often perform this action to remove evidence of their presence or malicious activities from a compromised system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the use of command-line tools like s5cmd or aws-cli to synchronize or copy data to an Amazon S3 bucket. The rule identifies suspicious patterns by looking for specific transfer commands combined with recursive or high-concurrency flags that indicate mass data movement often associated with exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects unauthorized attempts to access sensitive Veeam Backup and Replication credentials by querying the backend SQL database or directly accessing DPAPI Master Key files. This activity is indicative of an attacker attempting to decrypt backup credentials stored by the Veeam service.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the creation of scheduled tasks using 'schtasks.exe' or 'Register-ScheduledTask' where the task command path is located in suspicious directories such as AppData, Temp, or ProgramData, or where the task is configured to run under the SYSTEM account. This behavior is commonly used by adversaries for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Page 106 of 1870