Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects potential screen capture activity performed by either a suspicious executable (SearchTrustedRuntimeSvc.exe) that mimics a screen capture tool or a PowerShell script invoked by Node.js using .NET drawing libraries. This behavior is indicative of unauthorized information gathering, common in remote access trojans (RATs).
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
003
This rule detects network connections and DNS queries directed towards specific malicious domains or domains matching a pattern hosted on pages.dev, a service frequently abused for hosting malicious infrastructure such as phishing pages or command-and-control beacons.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
103
This rule monitors DeviceNetworkEvents and DnsEvents for connections to known malicious domains and IP addresses associated with phishing campaigns. It alerts on any network communication or DNS resolution attempt targeting these indicators, providing visibility into potential user interaction with phishing infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
003
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
103
Detects a multi-stage installation of the Level RMM agent. This rule monitors for a correlation of events including the execution of 'LevelInstaller.exe' with specific installation arguments, file drops in potentially spoofed vendor paths (Dell or Level), the creation of a 'Level' service, and the addition of a 'Level Watchdog' scheduled task on the same device within a 24-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
17 days ago
002
This rule monitors network traffic and DNS queries to identify endpoints attempting to connect to known cryptocurrency scam domains. It correlates data from DeviceNetworkEvents and DnsEvents to capture both direct network connections and DNS resolution attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
003
This rule detects suspicious PowerShell execution initiated by a Node.js process (node.exe). It monitors for command lines containing common bypass flags (-NoProfile, -NonInteractive, -ExecutionPolicy Bypass) and a specific string pattern 'wra-ps-', which is often associated with malicious scripts or remote access trojans (RATs) being executed via a Node.js application.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
003
Detects EDRKiller.exe or WarsawKiller.exe binaries and the associated wsftprm.sys BYOVD driver used by The Gentlemen threat actor to terminate security product processes
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
003
This rule detects network connections from monitored devices to known cryptomining pool IP addresses and domain names. It monitors DeviceNetworkEvents for indicators of compromise (IOCs) associated with cryptomining activities, identifying potential resource hijacking on internal endpoints.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
104
This rule detects network connections from monitored devices to known cryptomining pool IP addresses and domain names. It monitors DeviceNetworkEvents for indicators of compromise (IOCs) associated with cryptomining activities, identifying potential resource hijacking on internal endpoints.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
004
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
004
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
004
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
101
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
101
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
001
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
101
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
001
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
101
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects the use of the Windows Terminal Services console tool (tscon.exe) to hijack active or disconnected Remote Desktop sessions. Attackers often execute this with SYSTEM privileges, frequently initiated via service control utilities like sc.exe, schtasks.exe, or services.exe, to gain unauthorized access to user sessions without requiring credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
101
Page 166 of 1871