Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of the Chisel C2 tool by matching its unique command-line grammar, specifically the 'client' subcommand combined with reverse remote ('R:') configurations. This detection strategy is resilient against binary renaming and infrastructure rotation by focusing on the tool's required argument structure rather than static IOCs like filenames or C2 addresses. It is specifically useful for identifying unauthorized remote tunnels used for persistence and data exfiltration.
avatar
Yougesh Raj@yougesh
avatar
SlimKQL
21 days ago
107
The following analytic detects the installation of the XMRIG coinminer driver on a system. It identifies the loading of the `WinRing0x64.sys` driver, commonly associated with XMRIG, by analyzing Sysmon EventCode 6 logs for specific signatures and image loads. This activity is significant because XMRIG is an open-source CPU miner frequently exploited by adversaries to mine cryptocurrency illicitly. If confirmed malicious, this activity could lead to unauthorized resource consumption, degraded system performance, and potential financial loss due to unauthorized cryptocurrency mining.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
103
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
006
Detects instances where the legitimate Windows Character Map utility (charmap.exe) is spawned by suspicious processes or PowerShell, and subsequently loads clr.dll. This behavior is indicative of potential DLL sideloading or process injection techniques used by malware to execute arbitrary code within a trusted system process context.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
5017
This rule detects DNS queries or network connections originating from endpoints to a list of known malicious domains associated with various malware families (ClearFake, IClickFix, AMOS, Vidar, etc.). This helps identify potential C2 communication, malicious payload delivery, or infrastructure interaction.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
24 days ago
5015
This rule monitors for indicators of compromise (IOCs) associated with the ShinyHunters threat actor, including specific malicious domains, IP addresses, and artifacts found in command lines or event data. It aggregates telemetry from network events, Entra ID sign-in logs, cloud application activity, email logs, process execution, and general device events to detect interaction with known malicious infrastructure or execution of threat-actor specific artifacts.
avatar
F S@Fsdr
avatar
Detections.ai Community
25 days ago
16023
Detects attempts to dump credentials from the LSASS process memory, either by executing known credential dumping tools like Mimikatz, using command-line arguments indicative of credential harvesting, or performing suspicious memory access/dumping operations on the lsass.exe process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
109
This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
103
This rule monitors for the execution of an executable file (.exe) from a user's 'Downloads' directory followed shortly (within 5 minutes) by a network connection to port 4321, which is characteristic of the Bear C2 HTTPS-AES beacon pattern. This behavior is indicative of a potential secondary stage malware execution or C2 check-in after an initial user-driven download.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
000
This rule detects the execution of a file with an .exe extension from the user's Downloads directory that has been previously tagged with the Mark-of-the-Web (MOTW) Zone.Identifier. It correlates file creation events, the application of the MOTW alternate data stream, and subsequent process execution to identify potentially malicious downloaded executables.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
000
Detects network communication associated with the Bear C2 framework by identifying specific beacon URI patterns (/beacon?id=<uuid>) and connections to known non-standard listener ports (4321, 8080). The rule also monitors for process command lines containing specific hardcoded identifiers associated with this C2 implant.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
000
This rule monitors for the execution of an executable file (.exe) from a user's 'Downloads' directory followed shortly (within 5 minutes) by a network connection to port 4321, which is characteristic of the Bear C2 HTTPS-AES beacon pattern. This behavior is indicative of a potential secondary stage malware execution or C2 check-in after an initial user-driven download.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
000
This rule detects the execution of a file with an .exe extension from the user's Downloads directory that has been previously tagged with the Mark-of-the-Web (MOTW) Zone.Identifier. It correlates file creation events, the application of the MOTW alternate data stream, and subsequent process execution to identify potentially malicious downloaded executables.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
000
Detects network communication associated with the Bear C2 framework by identifying specific beacon URI patterns (/beacon?id=<uuid>) and connections to known non-standard listener ports (4321, 8080). The rule also monitors for process command lines containing specific hardcoded identifiers associated with this C2 implant.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
000
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
003
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
000
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
000
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
000
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
000
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
000
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
000
Page 160 of 1871