Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the execution of Windows Installer (.msi) files or screensaver (.scr) files that were recently downloaded and executed via a web browser. Attackers often use these file types as lures for fake updates or software installers to execute malicious code on the victim's system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects instances where cmd.exe or powershell.exe are launched from explorer.exe with command-line arguments containing DocuSign-themed keywords. This behavior is indicative of a 'ClickFix' phishing attack, where a user is socially engineered to copy and execute a malicious command via the terminal after interacting with a fraudulent DocuSign lookalike page.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects the silent installation or execution of Remote Monitoring and Management (RMM) tools when launched by script hosts (wscript.exe, mshta.exe, powershell.exe) which themselves were spawned by browser processes or explorer.exe. This pattern is characteristic of social engineering delivery chains, such as 'ClickFix', where a user is tricked into executing a script that subsequently fetches and runs RMM payloads for persistent remote access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects behavior indicative of the MLTBackdoor malware, specifically the creation or modification of a DLL file (such as *dlp.dll) shortly after or before the creation of an RC4-encrypted 'data.bin' file on the same host. The rule also looks for an optional preceding archive extraction event of common file types from Temp or Downloads directories by standard extraction utilities, which may indicate the staging of the initial payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects the execution of 'filemanager.exe' and its subsequent access to sensitive browser credential stores (e.g., 'Login Data', 'cookies.sqlite'), occurring within a short window following a PowerShell-based ClickFix-style attack chain. The rule correlates initial suspicious script execution (often involving hidden windows, obfuscated commands, or web requests) with follow-on credential harvesting behavior on the same host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects mshta.exe initiating outbound network connections, followed closely by the execution of a powershell.exe process with an unusually large command line, or PowerShell script block events containing large, potentially obfuscated scripts. This behavior is indicative of 'DeepLoad' or 'ClickFix' style staging, where legitimate binaries are leveraged to download and execute heavily obfuscated payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects potential credential theft or malicious browser extension installation (DeepLoad-style) by monitoring for browser extension manifest file drops or registry-based extension force-installs occurring shortly after suspicious PowerShell command execution (ClickFix-style) on the same device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects a sequence of activity where an endpoint performs multiple anti-analysis or sandbox evasion checks (using commands like wmic, powershell, or reg to query system information or look for debugger/VM artifacts) followed within 10 minutes by an outbound network connection to a domain that has not been observed from that specific device in the last 7 days.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects ClickFix-style fileless execution patterns where PowerShell pipelines (Invoke-RestMethod/Invoke-WebRequest) directly into execution cmdlets (Invoke-Expression/IEX) to download and execute remote scripts entirely in memory. The rule monitors for common bypass flags, hidden windows, and connections to suspicious IP address patterns or non-standard ports typically associated with malicious C2 staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
This rule detects a multi-stage attack pattern involving potential social engineering via lookalike conferencing domains. It identifies users visiting suspicious domains resembling well-known conferencing platforms (e.g., Teams, Meet, Zoom), followed by modifications to the Windows RunMRU registry key and subsequent execution of suspicious commands (PowerShell, CMD, mshta) by explorer.exe within a short timeframe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects potential supply chain attacks where a common external script (e.g., a widget) is loaded across multiple unrelated domains, followed by correlation with suspicious user-executed commands indicative of 'ClickFix' tactics (copying and pasting malicious code from a browser-based overlay into the Windows Run dialog).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects a potential ClickFix delivery attack where a user navigates to an automotive-themed website, interacts with the system via the Windows Run dialog (RunMRU), and subsequently executes command-line interpreters (powershell, cmd, wscript, mshta) spawned by explorer.exe within a short time window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
000
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
002
The following analytic identifies user accounts experiencing more than 5 account lockouts within a 5-minute time window.
It leverages the 'Change' data model and groups account lockout events into 5-minute time buckets to identify a high frequency of lockouts associated with the same user and destination.
This activity may indicate password spraying, brute-force activity, or repeated authentication attempts using invalid or outdated credentials.
If confirmed malicious, this behavior may indicate an attempt to gain unauthorized access to user accounts and could precede further compromise or lateral movement within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
004
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
17 days ago
103
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
17 days ago
103
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
303
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
003
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
202
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
102
Detects a behavioral fingerprint associated with the NeedyMantis group, characterized by the creation of a DLL and a identically-named, extensionless, encrypted archive file in the same directory within a short time window. This approach identifies the underlying packaging strategy rather than relying on static file names or known paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Page 133 of 1870