Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the execution of known remote access and support tools (Quick Assist, Microsoft Remote Assistance, or AnyDesk) on a host that has recently received a high volume of emails (over 50). This behavior often aligns with social engineering campaigns where a user is instructed to download or launch a remote support tool under false pretenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
001
Detects the exfiltration behavior of the Sauron Loader, where a process tree associated with rnpkeys.exe or its modules (rnp.dll, tdwp.dll) within the C:\ProgramData\keyroll directory performs a burst of numerous small HTTPS POST requests to a single destination. This pattern is characteristic of a screenshot image being fragmented into small chunks and exfiltrated.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
001
Detects the execution of suspected Sauron Loader components staged in C:\ProgramData\keyroll\ (rnpkeys.exe or tdwp.dll) followed by an outbound network connection from the same host within a 2-minute window. This behavior correlates the staging of malicious binaries with the loader's automated outbound registration attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
101
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
003
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
203
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
005
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
005
This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
205
IOC sweep against network telemetry for confirmed BengalSEO/MayaBot campaign infrastructure: the Hostmaza backend IP (5.101.140.80), Matomo tracking domains (stats.us3.org, us3.my), named MayaBot C2 domains (cus.cam, dll.lat, us99.org), and the ~170-domain Traffic Distribution System redirector fleet used to funnel victims to payload delivery. The source intel report contains no file hashes (MD5/SHA1/SHA256) -- only IPs, domains, and URLs -- so this sweep is IP/domain-only. Note the much larger corpus of single-use lure-page domains (~1,000 additional indicators) is excluded as too high-churn for static embedding.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
003
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
003
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
205
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
004
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
004
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
104
This rule detects activities indicative of an attacker attempting to establish an adversary-in-the-middle (AiTM) position within an on-premises network. It flags potential NTLM relay attempts (via loopback or invalid workstation indicators) and unauthorized name resolution spoofing (LLMNR/NBT-NS) used to intercept and relay authentication traffic for MFA bypass or credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the use of rundll32.exe to execute comsvcs.dll's MiniDump functionality against the LSASS process, a common technique for dumping credentials. The rule includes behavioral correlation by identifying the same user account executing this pattern on multiple devices within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
103
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
103
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
104
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
004
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
003
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
203
Page 115 of 1870