Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This analytic identifies the use of Chromium-based browsers (like Microsoft Edge) running in headless mode with the `--dump-dom` argument.
This behavior has been observed in attack campaigns such as DUCKTAIL, where browsers are automated to stealthily download content from the internet using direct URLs or suspicious hosting platforms.
The detection focuses on identifying connections to known file-sharing domains or direct IPs extracted from command-line arguments and cross-checks those against the destination of the flow.
Since it leverages Cisco Network Visibility Module telemetry, the rule triggers only if a network connection is made.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 day ago
000
This analytic detects system binaries that are commonly abused in process injection techniques but are observed without any command-line arguments.
It leverages Cisco Network Visibility Module (NVM) flow data and process arguments
to identify outbound connections initiated by curl where TLS checks were explicitly disabled.
Binaries such as `rundll32.exe`, `regsvr32.exe`, `dllhost.exe`, `svchost.exe`, and others are legitimate Windows processes that are often injected into by malware or post-exploitation frameworks (e.g., Cobalt Strike) to hide execution.
When these processes are seen initiating a network connection with an empty or missing command line, it can indicate
potential injection and communication with a command and control server.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 day ago
000
This analytic identifies the use of `msxsl.exe` initiating a network connection to a non-private IP address.
Although `msxsl.exe` is a legitimate Microsoft utility used to apply XSLT transformations, adversaries can abuse it
to execute arbitrary code or load external resources in an evasive manner.
This detection leverages Cisco NVM telemetry to identify potentially malicious use of `msxsl.exe` making network connections
that may indicate command and control (C2) or data exfiltration activity.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 day ago
000
This analytic identifies non-browser processes reaching out to public IP lookup or geolocation services,
such as `ipinfo.io`, `icanhazip.com`, `ip-api.com`, and others.
These domains are commonly used by legitimate tools, but their usage outside of browsers may indicate
network reconnaissance, virtual machine detection, or staging by malware.
This activity is observed in post-exploitation frameworks, stealer malware, and advanced threat actor campaigns.
The detection relies on Cisco Network Visibility Module (NVM) telemetry and excludes known browser
processes to reduce noise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 day ago
000
This analytic detects unexpected outbound network connections initiated by known webserver processes such as `httpd.exe`, `nginx.exe`, or `tomcat.exe` to common file sharing or public content hosting services like GitHub, Discord CDN, Transfer.sh, or Pastebin.
Webservers are rarely expected to perform outbound downloads, especially to dynamic or anonymous file hosting domains. This behavior is often associated with server compromise,
where an attacker uses a reverse shell, webshell, or injected task to fetch malware or tools post-exploitation.
The detection leverages Cisco Network Visibility Module flow data, enriched with process context, to identify this highly suspicious behavior.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 day ago
000
Detects the FileFix execution chain, where victims are socially engineered into pasting a malicious path into the Windows Explorer address bar. This action results in explorer.exe launching suspicious command-line tools (cmd.exe, powershell.exe, wscript.exe, or cscript.exe) with suspicious flags or unusually long, potentially obfuscated arguments characteristic of a 'ClickFix' style attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
108
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
203
This analytic detects the use of `curl.exe` with insecure flags such as `-k`, `--insecure`, `--proxy-insecure`, or `--doh-insecure`
which disable TLS certificate validation.
It leverages Cisco Network Visibility Module (NVM) flow data and process arguments
to identify outbound connections initiated by curl where TLS checks were explicitly disabled.
This behavior may indicate an attempt to bypass certificate validation to connect to potentially untrusted or malicious endpoints,
a common tactic in red team operations, malware staging, or data exfiltration over HTTPS.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 day ago
000
The following analytic identifies child processes spawned by spoolsv.exe, the Print Spooler service in Windows, which typically runs with SYSTEM privileges. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and parent process relationships. Monitoring this activity is crucial as it can indicate exploitation attempts, such as those associated with CVE-2018-8440, which can lead to privilege escalation. If confirmed malicious, attackers could gain SYSTEM-level access, allowing them to execute arbitrary code, escalate privileges, and potentially compromise the entire system.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
6 days ago
002
Detects execution of masqueraded wsl.exe binary.
Attackers can rename a malicious payload to wsl.exe to masquerade as the legitimate Windows Subsystem for Linux binary,
bypassing detection based on image name alone and abusing user trust in the WSL process name.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
6 days ago
102
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
8144
This rule detects activity involving known malicious indicators of compromise (IOCs), including specific IP addresses, domains, and file hashes. It monitors network connections, file system activity, process execution, and email attachments, filtering out common security tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
204
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
204
Detects files matching known SHA256 hashes of the masqueraded MSP360 RMM v2.5.0.67 installer and associated ScreenConnect/utility payloads used in phishing-to-dual-RMM campaigns
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
004
Detects the execution of known browser credential harvesting tools (WebBrowserPassView, WebBrowserBookmarksView, or WS_Password variants) from ScreenConnect temporary directories. This behavior often indicates post-compromise activity where an adversary uses an existing Remote Monitoring and Management (RMM) session to extract credentials from browsers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
204
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
003
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
103
Detects the use of common command-line utilities (net, powershell, cmd) to perform user account creation or local group membership modification, which are behaviors often associated with adversary persistence or privilege escalation.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
17 days ago
6040
Detects multiple attempts to disable, stop, or tamper with security products, backup solutions, or AV/EDR agents. The rule monitors for malicious use of sc.exe, net.exe, taskkill.exe, and PowerShell cmdlets targeting security software, as well as registry modifications to disable security protections. This behavior is commonly observed in post-compromise stages of ransomware attacks for defense evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
104
Detects a file named dnsapi.dll created/modified outside System32/SysWOW64/WinSxS (the only legitimate locations for the real system DLL). Now requires the file to BOTH land in one of the known NeedyMantis sideload staging folders AND match the published 3448-byte spoofed-config size -- previously the size check alone could match unrelated dnsapi.dll copies anywhere on disk; requiring both signals together removes that bypass.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
005
Detects anomalous authentication patterns where a single source IP targets a high number of unique user accounts with failed authentication attempts over a rolling window. By filtering out SSO/Federated methods and specific service account patterns, this rule isolates low-and-slow brute-force or password-spraying activities designed to evade standard account lockout mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
003
Page 12 of 1866