Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects Microsoft Office applications (Word, Excel, PowerPoint, etc.) launching common LOLBAS (Living Off the Land Binaries and Scripts) such as cmd, powershell, or wscript. This behavior is a common indicator of macro-based malware or document-based exploitation attempting to execute arbitrary code or scripts.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
15 days ago
001
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
001
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
001
This rule detects the addition or modification of Windows Firewall rules by applications residing in non-standard or suspicious directories. It monitors Security Events 2004, 2071, and 2097, filtering out known legitimate system paths, common temporary directories, and updates from trusted Microsoft processes such as Windows Defender, svchost.exe, and dllhost.exe. By excluding standard operating system folders and common software installation paths, the rule highlights potentially malicious attempts to establish persistence or facilitate unauthorized network communication by bypassing standard firewall management channels.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
003
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
001
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
101
Detects access to sensitive Active Directory objects associated with replication (specifically the Domain, Domain Controller, and Schema objects) by non-computer accounts, which may indicate an attempt to perform unauthorized replication or credential harvesting (e.g., DCSync attacks).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
008
Detects usage of the net1.exe utility to list members of the local 'Administrators' group in various languages. This technique is often used by adversaries for local system discovery during the reconnaissance phase.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects modifications to the WDigest 'UseLogonCredential' registry key. Enabling this setting (setting it to 1) forces the WDigest SSP to store plaintext credentials in memory, which facilitates easier credential harvesting by attackers using memory dumping techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
This rule detects potential web shells that employ steganographic techniques by embedding malicious executable script code within image file structures (JPG or PNG). It specifically flags files containing common web shell markers 'ONEPIECE' or 'x_best_911' in combination with embedded script tags (e.g., <script, eval, <%, <?php) within files identified as having image magic bytes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the creation or execution of a scheduled task named 'CreateObjectTask' via schtasks or PowerShell, which is associated with spawning 'dllhost.exe' as a child process under high-privileged parent processes (svchost, taskeng, or schtasks). This behavior is indicative of potential COM hijacking or privilege escalation techniques leveraging system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects web browser processes (e.g., Chrome, Edge, Firefox) spawned by parent processes that are not typical for web browser execution. This behavior is often associated with malware (such as infostealers) using unconventional process spawning to inject code or perform credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects JavaScript loaders associated with the Exvicy/ErrTraffic campaign. The rule identifies obfuscated code that utilizes atob() for Base64 decoding, single-byte XOR operations, TextDecoder for content processing, and dynamic code execution via 'new Function()'. This pattern is commonly used to inject malicious payloads into compromised WordPress sites.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects an attempt to exploit a directive injection vulnerability in the SharePoint 'WebPartPages.asmx' SOAP web service, specifically targeting the 'GetWebPartPageConnectionInfo' method. The rule looks for suspicious 'Register' directives in the request body, which could lead to unauthorized code execution or configuration manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the presence of a shared client-side JavaScript framework used in 'ClickFix' MaaS (Malware-as-a-Service) panels, specifically associated with the Exvicy and ErrTraffic campaigns. The rule identifies specific function patterns (e.g., xdReq, xdDec, waitForToken) and state machine logic (tokens, deduplication hashing) commonly used for token interception and clipboard interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
This rule detects specific JavaScript helper functions and state machine constants commonly used in 'ClickFix' phishing campaigns (e.g., Exvicy and ErrTraffic). These scripts typically prompt users to copy and paste malicious code snippets, often disguised as error fixes or CAPTCHA resolution, to facilitate initial access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
These rules detect various exploitation attempts targeting SharePoint to bypass SafeControls, an security mechanism used to restrict the types of controls allowed in web parts. The patterns match suspicious Register directives and markup injection techniques often associated with remote code execution or privilege escalation, as identified in CVE-2026-65660.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the IIS worker process (w3wp.exe) used by SharePoint loading a specific combination of assemblies (PresentationFramework.dll, System.Xaml.dll, and System.Data.Services.dll). This behavior is indicative of an ExpandedWrapper/XamlServices.Parse() insecure deserialization gadget chain, typically associated with the exploitation of vulnerabilities like CVE-2026-65660, which enables fileless in-memory code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects HTTP POST requests to SharePoint ToolPane or WebPartPage endpoints containing serialized gadget chains (e.g., ysoserial ExpandedWrapper/ObjectDataProvider or XamlServices) indicative of deserialization exploitation attempts, specifically targeting CVE-2026-65660.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects a suspicious execution chain where explorer.exe (typically via the Run dialog) executes PowerShell, which subsequently launches msiexec.exe to silently install the PuTTY SSH client. This sequence is characteristic of the 'ClickFix' technique, which uses social engineering to trick users into running malicious commands for remote access deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
102
Detects instances where the SharePoint IIS worker process (w3wp.exe) initiates command interpreters or known living-off-the-land binaries (LOLBins). This behavior is characteristic of post-exploitation activity, such as command execution following successful exploitation of SharePoint vulnerabilities involving insecure deserialization or malicious directive injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Page 168 of 1871