Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the loading of a legitimately signed but vulnerable driver from suspicious directories (e.g., Temp, Downloads) followed closely by the termination of critical security/EDR service processes. This sequence is indicative of Bring Your Own Vulnerable Driver (BYOVD) exploitation used to disable security controls prior to ransomware deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects scripting interpreters (wscript.exe, cscript.exe, powershell.exe, python.exe) that perform an outbound network connection to known public Generative AI API endpoints and subsequently modify their own script file on disk. This behavior is indicative of sophisticated malware attempting to rewrite its own source code at runtime to evade signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects a credential stuffing attack characterized by a high volume of failed authentication attempts from a small set of source IP addresses followed by a successful authentication within a short timeframe. This behavior is indicative of an attacker attempting to use valid credentials obtained from infostealer logs or credential leaks to gain unauthorized access to accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
This rule detects potential lateral movement by identifying a system that initiates SMB connections (port 445) to 5 or more unique destinations, correlated with a Windows Service installation event (Event ID 7045) on the host. This behavior is indicative of an adversary or automated tool using SMB to copy and execute binaries as a service on multiple remote systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
This rule detects successful user logins from multiple geographical locations (impossible travel) where multi-factor authentication (MFA) was not utilized. This behavior is indicative of credential theft or account takeover attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
This rule detects a correlation between an Active Directory Certificate Services (AD CS) certificate request (Event ID 4887) containing certificate attributes (SAN, altname, or UPN) and a subsequent Kerberos TGT request (Event ID 4768) within an hour, where the requested account name does not match the ticket user. This behavior is indicative of potential certificate-based authentication abuse, such as 'ESC1' or 'Golden Certificate' attacks where a certificate is requested and immediately used for credential impersonation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects the use of common administrative tools (vssadmin, wbadmin, wmic, bcdedit, etc.) to perform actions that inhibit system recovery. This includes deleting Volume Shadow Copies, deleting backup catalogs, disabling system recovery boot policies, and stopping backup-related services, which are common behaviors used by ransomware to prevent data restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects the installation of a new Windows service where the executable path is located in suspicious or uncommon directories (e.g., Temp, Users, AppData) or uses known living-off-the-land binaries (LotLBin) in the command path. This pattern is commonly used by adversaries for persistence and privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) using weak encryption (RC4/0x17) directed at multiple unique Service Principal Names (SPNs) from a single host or user within a short timeframe. This behavior is indicative of Kerberoasting, a technique used by attackers to harvest service account credentials for offline brute-force cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects a single host or account generating a high volume of LDAP queries (typical of reconnaissance tools like BloodHound/SharpHound) within a 10-minute time window. The rule specifically looks for more than 500 LDAP queries targeted at a limited number of Domain Controllers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects instances where PowerShell is executed with encoded commands, seemingly spawned by a process masquerading as or related to the Microsoft Edge Update Task. The rule specifically monitors for process chains involving 'conhost.exe' with '--headless' arguments and subsequent PowerShell execution containing encoded commands, often associated with obfuscated activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
004
Detects NTLM network logon events (Logon Type 3) using the NtLmSsp process where the key length is zero. This pattern is often indicative of Pass-the-Hash (PtH) attacks where the adversary uses a NTLM hash for authentication without knowing the original plaintext password.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects usage of the Windows certutil.exe utility with flags commonly used by adversaries to download files from remote URLs or decode base64 encoded files. These techniques are often utilized for ingress tool transfer or deobfuscating malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects the execution of PowerShell commands that enumerate files within sensitive user directories such as Desktop, Downloads, Documents, or OneDrive, using common cmdlets like Get-ChildItem with recurrence or filtering. This behavior is indicative of an adversary attempting to discover or stage files for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
004
Detects instances where a trusted, system-protected executable loads a DLL file from a user-writable or temporary directory that is not digitally signed or has an invalid signature. This is a common indicator of DLL side-loading or DLL hijacking, where an adversary attempts to execute malicious code by placing a malicious DLL in a location searched by a legitimate process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects the use of the BITSAdmin command-line utility to perform file downloads or add files to a transfer job. Adversaries may abuse the Background Intelligent Transfer Service (BITS) for downloading malicious files while evading detection or maintaining persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects the use of net.exe or net1.exe to establish an IPC$ share connection. This is a common method for lateral movement and reconnaissance by attackers to verify administrative access or interact with remote systems via SMB. The rule specifically flags commands involving the IPC$ share, with logic to identify if a specific user was specified or if an anonymous session was attempted.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
004
This rule detects rundll32.exe executing a DLL from the ProgramData directory and subsequently establishing five or more outbound network connections to external IP addresses over non-standard ports (excluding 80 and 443) within a one-hour window. This behavior is indicative of a potential malware beaconing or data staging activity using a proxy binary to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects specific file artifacts associated with an AsyncRAT infection chain that leverages a renamed AutoIT interpreter. The rule looks for the presence of a renamed executable, an encrypted .ini loader script, and an unnamed binary payload staged within a temporary directory, as well as associated batch script activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of PowerShell (powershell.exe or powershell_ise.exe) initiated by Windows Script Host (wscript.exe or cscript.exe). The rule specifically looks for common obfuscation and stealth flags such as hidden window style, execution policy bypass, and non-interactive mode, which are often used by malicious scripts to execute code silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
503
Page 162 of 1871