Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
104
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
004
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
003
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
203
Detects attempts to disable Windows Defender by either executing known Defender Control utilities or by modifying registry keys associated with the disabling of anti-spyware features or the WinDefend service startup.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
000
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
505
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
205
Detects the clearing of Windows Security Event Logs (EventID 1102) within 15 minutes of a successful user logon (EventID 4624) on the same host. This activity is a common anti-forensics technique used by adversaries to hide malicious actions following an authenticated session.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
305
Detects the stopping or modification of critical security and backup services on Windows endpoints. This behavior often indicates an attempt by an adversary to impair defensive capabilities or disable logging to facilitate malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
105
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
105
This rule detects attempts to exploit the Microsoft Support Diagnostic Tool (MSDT) vulnerability CVE-2022-30190, known as 'Follina'. The rules monitor for malicious HTTP traffic and payloads that leverage the 'ms-msdt' URI scheme to execute arbitrary commands, often delivered via weaponized documents or external references to remote malicious HTML files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
000
Detects network traffic patterns characteristic of the EternalBlue (MS17-010) exploit targeting the SMBv1 protocol. Specifically, it monitors for a malformed SESSION_SETUP request containing an unusually large payload, which is indicative of an attempt to trigger a buffer overflow in the SMB service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
000
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
004
Detects sequential suspicious SMB activity characteristic of PsExec lateral movement: connection to ADMIN$ or C$ administrative shares, followed by the upload of an executable or batch file to the share, and subsequently the usage of SVCCTL (CreateServiceW/StartServiceW) to execute the uploaded binary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
000
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
101
Detects an Active Directory Certificate Services (AD CS) Certificate Enrollment Service (CES) SOAP request that includes a 'CertificateTemplate' item in the 'AdditionalContext' body, potentially indicating a directed attempt to request a specific certificate template during enrollment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
This rule detects potential NTLM relay or authentication downgrade attempts by monitoring HTTP POST requests to the Certificate Enrollment Service (CES) endpoint. It specifically flags when an 'Authorization' header contains an NTLM-wrapped 'Negotiate' token, which is often indicative of an attacker attempting to coerce or relay authentication material to the service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
17 days ago
104
The following analytic identifies instances where CrushFTP has blocked access due to exceeding the maximum number of simultaneous connections from a single IP address. This activity may indicate brute force attempts, credential stuffing, or automated attacks against the CrushFTP server. This detection is particularly relevant following the discovery of CVE-2025-31161, an authentication bypass vulnerability in CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
005
The following analytic detects Log4Shell JNDI payload injections via outbound connections. It identifies suspicious LDAP lookup functions in web logs, such as `${jndi:ldap://PAYLOAD_INJECTED}`, and correlates them with network traffic to known malicious IP addresses. This detection leverages the Web and Network_Traffic data models in Splunk. Monitoring this activity is crucial as it targets vulnerabilities in Java web applications using log4j, potentially leading to remote code execution. If confirmed malicious, attackers could gain unauthorized access, execute arbitrary code, and compromise sensitive data within the affected environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
005
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
003
Page 116 of 1870