Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the misuse of the legitimate odbcconf.exe utility via the /A switch combined with the REGSVR action. Attackers leverage this behavior to execute malicious DLLs, often utilizing response files or executing from non-standard directories to bypass application control policies.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
101
Detects the creation of a scheduled task configured to run under SYSTEM or a Service account, where the triggering process is not a recognized system binary (e.g., taskeng.exe, schtasks.exe). This pattern is often used for persistence or lateral movement by bypassing standard administrative task creation tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
007
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects the use of sdbinst.exe to install a shim database (.sdb) file from non-standard, user-writable directories (such as Temp, AppData, Downloads, Users Public, or ProgramData). Adversaries use application shimming to achieve persistence or privilege escalation, and custom shims are typically expected to reside in system-protected AppPatch directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects network connection attempts to known malicious infrastructure, specifically targeting suspicious domains and an IP address associated with command and control (C2) activity. The rule monitors endpoint network events for communication with specified malicious URLs or a hardcoded IP.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
101
This rule detects potentially malicious network activity by monitoring for specific query parameters ('bmodule', 'smodule', 'lmodule', 'task', 'upload.php') in web requests or communication with a specific known-malicious IP address ('62.60.226.50'). This pattern is characteristic of C2 (Command and Control) traffic or unauthorized file staging/upload operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
101
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
001
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
101
Detects execution of MeshAgent binaries when initiated by common scripting or application processes (e.g., java, sh, bash, python) or when displaying suspicious command-line patterns indicative of unauthorized remote access or download activity, particularly in environments like WebLogic or PeopleSoft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
000
Detects a specific pattern associated with AvisLoader or similar malware: a device establishes a network connection to known Cloudflare Tunnel infrastructure domains (trycloudflare.com or workers.dev), followed by the creation and execution of an executable file (.exe, .dll, or .scr) in user-writable directories such as Downloads, AppData, or Temp within a 15-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
This rule detects the presence and execution of known suspicious files (hashes provided) or specific malicious artifacts, such as 'hmn_hook.dll' being loaded, or the execution of binaries named 'auto.exe' and '78324.exe' associated with specific command-line arguments. It monitors file events, image loads, and process creation to identify potential malware activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
This rule identifies instances of screen capture events initiated by processes that have previously engaged in network communication with known Remote Management Tool (RMM) domains. By correlating network activity with suspicious endpoint events, it flags potential unauthorized screen scraping performed by tools often abused by attackers for post-compromise reconnaissance.
avatar
F S@Fsdr
avatar
Detections.ai Community
24 days ago
9015
Detects malformed HEIF/HEIC image files with anomalous ftyp/box structure consistent with the libheif memory corruption exploit (CVE-2026-32882) used against Discourse forum image upload endpoints
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
005
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
22036
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
001
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
001
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
001
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
101
Detects the use of Windows Management Instrumentation (WMI) utilities (wmic.exe or wmiprvse.exe) to perform command execution or establish persistence via WMI event subscriptions, filters, or consumers. Attackers often abuse these WMI features to execute arbitrary commands, run payloads, or establish persistent backdoors.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
15 days ago
001
Page 167 of 1871