Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
103
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
603
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
103
Detects anomalous access to the SharePoint WebPartPages.asmx SOAP endpoint, specifically using the GetWebPartPageConnectionInfo method. This query identifies patterns consistent with the exploitation of CVE-2026-65660, where adversaries attempt to smuggle WebPart template markup (e.g., <%@ Register, XamlServices) after legitimate preview methods have been disabled.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
007
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
2 days ago
000
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
2 days ago
000
Detects the OIC-lure Mustang Panda PlugX infection chain with tightened false-positive controls: requires the console-resize artifact (mode.com with digit,digit args) that precedes the download, requires PowerShell to be parented directly by explorer.exe (filtering out legitimate scheduled-task/management-agent automation that also chains curl+tar), requires curl to combine -L with -k/-s (insecure/silent) flags, narrows all correlation windows to 2 minutes, and excludes shell/utility processes from the final execution match.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
2 days ago
000
This rule detects successful network connections to known malicious IP addresses or the domain 'forgitlab.com', which are associated with the Azazel malware threat infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
2 days ago
000
This rule detects successful network connections to known malicious IP addresses or the domain 'forgitlab.com', which are associated with the Azazel malware threat infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
2 days ago
000
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
003
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
003
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
003
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003
This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools when initiated from suspicious parent processes (such as browsers, office applications, or command-line interpreters), originating from common writeable directories (e.g., Temp, Downloads), or executed with command-line arguments indicative of silent/unattended installation. This behavior is often associated with initial access, persistence establishment, or unauthorized remote control of a system.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
103
Detects techniques commonly used to dump Active Directory domain credentials by accessing the NTDS.dit database file. This includes the use of ntdsutil for IFM (Install From Media) operations, manual shadow copy creation using vssadmin or wmic to copy the ntds.dit file, direct access to shadow copy volumes containing sensitive database files, and the use of credential dumping tools like Impacket's secretsdump.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
003
Detects the abuse of the Windows built-in utility 'certutil.exe' to download files from remote locations using the 'urlcache', 'verify', or 'verifyctl' arguments. Attackers often leverage this LOLBIN to download malicious payloads as it is a trusted system binary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
0016
The following analytic identifies a popular 3rd party software process being executed where it's process name does not match it's original file name attribute.
Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 days ago
000
Detects attempts to inhibit system recovery by deleting Volume Shadow Copies or modifying Windows Boot Configuration Data, a technique commonly employed by LockBit and other ransomware families prior to file encryption.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
003
Detects msiexec.exe spawned from explorer.exe, consistent with a user double-clicking a malicious .lnk shortcut, where the command line triggers the installation of an MSI package hosted on a remote HTTP/HTTPS server. This behavior is a known initial access technique used by FIN7 to deliver malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
303
Page 13 of 1866