Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects instances where FortiClient EMS management daemon processes (FCMDaemon.exe, FortiClient_Server.exe, or FCMWebServer.exe) spawn suspicious child processes often associated with living-off-the-land techniques, such as command shells, scripting interpreters, or system administrative utilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects the loading of Python DLLs (python36.dll or python37.dll) from suspicious, non-standard user-writable directories such as Downloads, Temp, or AppData, which may indicate a DLL sideloading attempt.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects the use of PowerShell to modify Windows Defender exclusions by adding a path or process located in user-controlled directories (Downloads, Temp, AppData). This behavior is characteristic of adversaries attempting to suppress security alerts for malicious binaries masquerading as legitimate software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
004
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
207
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
304
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
004
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
304
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
304
Detects the use of native Windows utilities such as vssadmin.exe, wmic.exe, and diskshadow.exe to delete volume shadow copies. This is a common technique used by ransomware and other malware to prevent system recovery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
204
This rule detects modification of the Windows Registry to disable the Windows Firewall. Specifically, it monitors for EventID 4657 (A registry value was modified) where the 'EnableFirewall' value is set to '0' within the FirewallPolicy service registry path, indicating an attempt to disable the host-based firewall.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
304
Detects the creation or execution of a scheduled task named 'CreateObjectTask' via schtasks or PowerShell, which is associated with spawning 'dllhost.exe' as a child process under high-privileged parent processes (svchost, taskeng, or schtasks). This behavior is indicative of potential COM hijacking or privilege escalation techniques leveraging system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the use of PowerShell to perform COM database enumeration, often associated with OleViewDotNet or NtObjectManager tools, specifically looking for indicators of COM object querying such as InProcServer32 path identification.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
This rule detects the use of PowerShell cmdlets often associated with enumerating COM object registrations, specifically targeting 'InProcServer32' registry keys. Such enumeration is a common reconnaissance step for identifying 'dangling' COM objects—registrations that point to missing or non-existent files—which can be exploited to achieve DLL Hijacking or persistence via COM hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the dllhost.exe process, running with SYSTEM privileges, loading a dynamic link library (DLL) from a user-writable path within the ProgramData directory. This behavior is consistent with the abuse of COM marshaling, specifically exploiting dangling CLSID entries to force a privileged COM host process to unmarshal and load an attacker-controlled DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
This rule detects the presence of Vidar Stealer version 2.0+ by identifying the specific ARX-based (Addition-Rotation-XOR) stream cipher implementation. The detection logic searches for stable cryptographic constants (FNV-1a prime and golden-ratio constants), unique per-build ARX transformation constants, and specific post-decryption artifacts in the file's binary content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the accumulator-based virtual machine (VM) skeleton used by Vidar Stealer (v2.0+) to obfuscate its internal configuration and strings. The rule specifically identifies a combination of bit-manipulation and arithmetic primitives (ROR, ROL, NOT, IMUL, ADD, SUB, XOR) acting as a dispatcher pattern within highly entropic executable sections, which is a characteristic behavioral artifact of the Vidar Stealer obfuscation engine.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the presence of specific .NET deserialization gadget chain components (ExpandedWrapper, XamlServices, ObjectDataProvider, LosFormatter) within application traffic or logs, which are indicative of exploitation attempts targeting SharePoint pre-authentication remote code execution vulnerabilities like CVE-2026-65660.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects malicious HTTP POST requests targeting SharePoint servers that attempt to inject 'Register' directives into pages or manipulate WebPartPage ToolPane markup, indicative of attempts to bypass SafeControls or exploit vulnerable SharePoint features for code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects JavaScript code within HTML pages designed to block browser developer tools (F12, Inspect, View Source) using keydown event listeners. This technique is commonly associated with ClickFix-style phishing campaigns to prevent users or security analysts from inspecting malicious page content or fake CAPTCHA overlays.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects malicious exploitation attempts against the SharePoint WebPartPages.asmx SOAP endpoint. Attackers use this endpoint to bypass security patches by invoking template-parsing functions like GetWebPartPageConnectionInfo, which facilitates Register-directive injection and XamlServices deserialization chains for remote code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Page 135 of 1870