Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects lateral movement activities associated with The Gentlemen ransomware group. The rule monitors for the execution of PowerShell scripts named 'deploy_gpo.ps1' from the %TEMP% directory, PowerShell interactions with the NETLOGON share for malware distribution, creation of ScheduledTasks.xml via PowerShell (a common GPO manipulation technique), and the subsequent enforcement of policy changes using 'gpupdate /force' invoked by scripting engines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects attempts to terminate security-related processes (AV/EDR) using common administrative tools including taskkill.exe, wmic.exe, and PowerShell Stop-Process. This behavior is frequently observed during the pre-encryption phase of ransomware attacks, such as Nova and Gentlemen, to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
201
Detects lateral movement activities associated with The Gentlemen ransomware group. The rule monitors for the execution of PowerShell scripts named 'deploy_gpo.ps1' from the %TEMP% directory, PowerShell interactions with the NETLOGON share for malware distribution, creation of ScheduledTasks.xml via PowerShell (a common GPO manipulation technique), and the subsequent enforcement of policy changes using 'gpupdate /force' invoked by scripting engines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the specific sequence of administrative utilities used by Gentlemen ransomware to seize control of files before encryption. This involves using 'takeown.exe' to claim ownership, 'icacls.exe' to grant full access to the Everyone group, and 'attrib.exe' to remove read-only file attributes, a common precursor to mass file encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the mass termination of security, backup, database, and virtualization services and processes. The rule monitors for the use of 'taskkill', 'sc', and 'net stop' commands, targeting a list of processes and services often associated with pre-encryption cleanup activities by ransomware actors to neutralize security tools and data access controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
201
Detects the creation of hidden administrative shares (ending in $) mapped to local directories (e.g., C:\Temp) with unrestricted 'Everyone' or 'ANONYMOUS LOGON' permissions. This technique is used by the Gentlemen ransomware to stage malicious binaries for lateral movement and subsequent encryption across the network. The rule monitors for 'net share' commands with specific permission grants, 'icacls' operations modifying access for anonymous users, and registry changes to 'NullSessionShares' configurations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the creation of scheduled tasks using schtasks.exe initiated by command shells where the task command points to files residing in non-standard or user-writable directories such as \Users\Public\, \PerfLogs\, or \ProgramData\. This pattern is frequently utilized by malware loaders like SocGholish, GootLoader, and various ransomware strains to achieve persistence following initial compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the execution of Nova ransomware (formerly RALord) by monitoring for its specific modular command-line interface arguments, which include file encryption commands, ransom note deployment, and specific ransom note filenames. The rule monitors process creation events for strings like 'encrypt-all', 'encrypt-path', 'readme-add', '--workers', and the presence of the 'README_NOVA.me' ransom note or unique file extensions associated with its encryption activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
201
Detects a sequence where an AWS Secrets Manager secret is retrieved via CloudTrail, followed within 30 minutes by an EDR-monitored process initiating an outbound network connection on a non-standard port (not 80 or 443). This behavior is consistent with an adversary using stolen credentials to pivot into a persistent command-and-control channel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects the suspicious combination of PowerShell scripts executing download commands (Invoke-WebRequest, etc.) while initiated by scripting hosts (wscript.exe, cscript.exe), followed by activity associated with remote support tools (LogMeIn, ConnectWise, etc.). It also identifies network connections associated with these remote management platforms, suggesting potential unauthorized remote access or tool staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects outbound network requests to Google Gemini AI API endpoints from processes that are not common web browsers or known development tools. This behavior is indicative of unauthorized use of LLM services by non-browser applications, such as the RatHat UI-automation module, for processing sensitive data or automation tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects a browser process downloading an APK installer file from a source other than official Google Play infrastructure. This behavior is commonly associated with smishing, malvertising, and redirection to deceptive third-party application portals used to distribute malware-laced APK droppers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects endpoint network activity characterized by a host connection to the Telegram Bot API followed by a connection to a Vercel-hosted domain within 30 minutes. This behavior is indicative of a multi-stage infection chain where adversaries use Telegram for command-and-control communication or victim validation, followed by the retrieval of malicious payloads or lures from disposable infrastructure like Vercel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
101
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
101
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
101
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
101
Detects HTTP requests and responses involving the download of an executable file named 'ClaudeDesktop.exe' from the 'claude.ai' host, which is indicative of a malicious campaign distributing SectopRAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects potential malicious activity where a process associated with a Claude agent (or a downloader utility) references a 'SKILL.md' configuration file. This behavior is indicative of a poisoned skill file being used to trigger unauthorized payload downloads or re-establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects network activity associated with the JWR/Outsider phishing kit, which leverages legitimate e-commerce platform parameters (e.g., Shopify/WooCommerce 'cart_data') to mimic storefront infrastructure. The rule correlates requests containing these e-commerce parameters with the loading of the phishing kit's client-side engine scripts or WebSocket workers from the same host, indicating the use of a compromised or malicious storefront-mimicry domain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects outbound network connections to known JWR phishing framework endpoints. The rule identifies suspicious interaction sequences, including initial beaconing via 'addClick' or 'getSyncSettings' followed by exfiltration of sensitive data (payment card info, OTPs) through POST requests to 'the_final_interface' or 'addCvv', or via a specific WebSocket channel pattern.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Page 157 of 1871