Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a process obtaining handle access to the LSASS process (Sysmon Event ID 10) followed by the creation of a file (Sysmon Event ID 11) using an extension other than '.dmp'. This behavior is characteristic of adversaries attempting to obfuscate credential dumping activities by bypassing simple extension-based detection rules.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects web application server processes (such as IIS, Apache, Tomcat, Java, Nginx, or Node.js) spawning command-line interpreters or system utilities. This behavior is frequently associated with webshell execution or post-exploitation activities following the exploitation of a public-facing application, often seen in VPN or enterprise software compromises.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the creation of files commonly associated with ransomware notes (e.g., README.txt, HOW_TO_DECRYPT.txt) across multiple directories, which is a strong indicator of the impact phase where files have been encrypted and the adversary is providing recovery instructions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the use of the bcdedit.exe utility to configure the Windows boot configuration to enter Safe Mode (minimal or with networking), immediately followed by the execution of a shutdown command with the reboot flag. This sequence is a known technique utilized by Akira ransomware affiliates to force a system reboot into a restricted environment where security agents and endpoint detection and response (EDR) tools may fail to load, allowing for undetected encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a burst of lateral movement activity characterized by the use of administrative tools like PsExec or NetExec/CrackMapExec to execute commands or services on multiple distinct target hosts from a single source host within a short window. This pattern is commonly associated with ransomware affiliates or threat actors performing reconnaissance and mass deployment of malicious payloads prior to encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects remote command execution patterns associated with the Impacket suite (e.g., wmiexec.py, atexec.py, smbexec.py). The detection identifies cmd.exe processes spawned by WmiPrvSE.exe or svchost.exe that contain specific command-line arguments indicative of Impacket's remote execution behavior, such as output redirection to hidden administrative shares or temporary files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of rclone.exe or renamed binaries with command-line flags indicative of data exfiltration to cloud storage providers such as S3, Mega, OneDrive, or Google Drive. This behavior is frequently associated with ransomware actors, including Akira, Qilin, and Storm-2570, who use Rclone to perform mass exfiltration of sensitive file share data prior to encryption (double extortion).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects unauthorized attempts to dump credentials from the Local Security Authority Subsystem Service (LSASS) process. This includes the execution of known credential-harvesting tools (e.g., Mimikatz, LaZagne, pypykatz), the use of system utilities like procdump and comsvcs.dll to dump process memory, and anomalous direct handle access to lsass.exe by non-system processes. This activity is associated with Storm-2570 post-compromise tradecraft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects Active Directory Directory Replication Service (DRSUAPI) GetNCChanges requests originating from a principal or host that is not recognized as a Domain Controller. This behavior is indicative of unauthorized DCSync operations used to dump NTDS.dit hashes, a common technique for credential harvesting associated with ransomware actors like Qilin.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of reconnaissance commands designed to enumerate Active Directory domain trust relationships. Attackers, including those associated with ransomware operations like INC Ransom, use these tools to map organizational structures and identify pathways for lateral movement and cross-domain propagation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of reconnaissance commands designed to enumerate Active Directory domain trust relationships. Attackers, including those associated with ransomware operations like INC Ransom, use these tools to map organizational structures and identify pathways for lateral movement and cross-domain propagation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the creation of scheduled tasks using schtasks.exe that exhibit behaviors associated with common remote execution tools (e.g., Impacket's atexec.py) or staging from insecure directories like Temp, ProgramData, or network shares. These patterns are frequently used by threat actors, including INC Ransom, for lateral movement and remote execution of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a multi-stage extortion tactic where a host is targeted by a mass creation of initial decryption-style ransom notes across multiple directories, followed by a subsequent drop of distinct follow-up 'press release' or 'threat' notes within a 30-minute window, indicative of INC Ransom behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects unauthorized modification or creation of registry keys under HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\ to maintain persistence for remote access/RMM tools during Safe Mode with Networking. This technique is used by Akira ransomware affiliates to evade EDR and security software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects behavioral patterns associated with the Everest ransomware loader, specifically the execution of a .NET host process from a non-standard parent, potentially indicating process injection, combined with network activity indicative of lateral movement or discovery, such as Wake-on-LAN packets or SMB scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects usage of the 'gem' command (install, build, push, publish) that includes naming patterns or specific command strings associated with the GemStuffer supply chain compromise campaign. This targets attempts to introduce malicious dependencies into the environment using RubyGems.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
6024
This rule detects the loading of the 'vsstrace.dll' module by processes that are not standard system processes or authorized software. The 'vsstrace.dll' is a library used by the Volume Shadow Copy Service (VSS). Unauthorized or unexpected processes loading this DLL may indicate an attempt to interact with or manipulate volume shadow copies, which is a common behavior for ransomware attempting to inhibit system recovery.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
106
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
306
This rule detects the creation of scheduled tasks on a remote host via the Task Scheduler RPC interface (opnum 1, RegisterTask). This interface is commonly abused by lateral movement tools such as Impacket's atexec, SharpTask, and SynkLoader to execute code or establish persistence on a remote system.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
14 days ago
002
Detects a multi-stage loader execution chain, potentially named GHAPPIER, by identifying sequential stages of execution. These stages include initial marker file checks, shell-based command dispatching via curl/wget, renaming and execution of secondary payloads, Node.js-based runtime staging, and the eventual creation of implant artifacts in common paths such as VSCode extensions or hidden directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
006
Detects suspicious PowerShell process execution initiated by Windows Explorer, specifically involving WebDAV-related commands or network share mounting indicators. This pattern is commonly associated with attackers attempting to download and execute remote payloads from WebDAV shares to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
506
Page 107 of 1870