Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the clearing of the Windows Security event log, which generates Event ID 1102. This action is often performed by adversaries to cover their tracks after performing malicious activities on a compromised host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
104
Detects anomalous SOAP requests to the SharePoint WebPartPages.asmx endpoint specifically targeting the 'GetWebPartPageConnectionInfo' method. This pattern is associated with exploitation attempts against SharePoint vulnerabilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
004
Detects the installation and execution of MeshAgent, a remote monitoring and management (RMM) tool, by identifying specific command-line arguments, service names, and renamed binary execution. Adversaries often use RMM tools for persistent remote access and command and control.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
304
This rule monitors network connections initiated by common web browsers (chrome.exe, msedge.exe, brave.exe) to known domains associated with a specific VPN proxy service or subscription-based proxy farm infrastructure. The rule flags endpoints communicating with URLs involved in proxy beaconing, fallback hosting, and subscription API calls.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
203
Detects instances where the Microsoft Edge proxy process (msedge_proxy.exe) initiates command-line interpreters such as cmd.exe, powershell.exe, or pwsh.exe. This behavior is highly suspicious as a browser-related process should not typically be spawning shell interpreters, potentially indicating exploitation of browser vulnerabilities or malicious script execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
404
Detects anomalous process execution (cmd.exe, powershell.exe, wmic.exe, tasklist.exe, taskkill.exe) initiated by the process 'ReportDump.exe'. This activity is indicative of the SectopRAT payload performing remote shell, file management, or process control tasks initiated via a C2 channel.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
103
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
10020
Detects suspicious process-injection related API calls (such as CreateRemoteThread, VirtualAllocEx, and WriteProcessMemory) where the source or target process is a common AI agent runtime environment (e.g., python.exe, node.exe, java.exe, dotnet.exe). This detects potential malicious code execution or reflective loading initiated by or targeting these runtime processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
203
Detects when an AI agent's code execution sandbox (e.g., Python, Node.js, or Shell interpreters) initiates suspicious child processes. This includes the execution of network utilities for potential C2 (e.g., curl, nc, socat), the creation of interactive reverse shells, or the execution of credential harvesting tools (e.g., mimikatz, secretsdump), which suggests the AI agent's sandbox environment has been compromised or abused.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
203
Detects the abuse of the CMSTPLUA COM object, a known technique for UAC bypass, to execute a hidden and non-profile PowerShell process. This behavior is associated with malicious activity chains like RemotePanel or BoundSiphon that aim to achieve elevated execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
004
Detects instances where the SQL Server process (sqlservr.exe) initiates command-line utilities such as cmd.exe or powershell.exe, and further identifies suspicious command-line arguments often associated with post-exploitation activity like discovery, credential gathering, or file manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
204
This rule detects a potential brute force attack against the Microsoft SQL Server 'sa' administrative account. It identifies a high volume of failed authentication events (Event ID 18456) for the 'sa' account within a 10-minute window, followed by a successful authentication event (Event ID 18453 or 18454) from the same source IP address. The rule specifically filters for successful logins originating from non-private (internet-facing) IP addresses, suggesting an attempt from an external threat actor.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
004
Detects a sequence of events where a suspected sideloaded process (e.g., masquerading as common tools like curl or vim) is followed within 30 minutes by the registration of a new Windows service, a behavioral pattern associated with the NeedyMantis threat group.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
004
Detects a suspicious sequence of events characteristic of NeedyMantis's hands-on-keyboard activity. The rule identifies file staging (creation or modification of suspicious DLLs from network shares) followed by remote command execution (via Impacket-like service interaction) and subsequent execution of binaries vulnerable to DLL sideloading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
004
This rule monitors for sustained, repeated network connections from specific processes (often legitimate binaries used by the NeedyMantis group for loader activities) to known NeedyMantis-associated C2 domains. It triggers when an initiating process, associated with known loader activity, maintains a persistent communication pattern consistent with an active WebSocket C2 session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
004
Detects the execution of the encryptbase64.ps1 PowerShell script when invoked by a process other than PowerShell or PowerShell Core. This behavior is indicative of NeedyMantis malware attempting to evade detection by executing scripts outside standard script hosts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
004
Detects suspicious command execution patterns involving cmd.exe or powershell.exe spawned by services.exe, or involving redirection to temporary files, which are consistent with Impacket-based remote service execution commonly associated with NeedyMantis malware deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
004
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
305
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
207
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
107
Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
17 days ago
16137
Page 14 of 1866