Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential lateral movement by identifying NTLM authentication (Logon Type 3) to administrative network shares (ADMIN$, C$, IPC$) or high-frequency access to multiple hosts by the same user, which may indicate credential abuse or lateral movement attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects instances of Kerberos Ticket-Granting Ticket (TGT) requests (Event IDs 4768 and 4769) that utilize the legacy RC4 encryption type (0x17). In modern Active Directory environments where AES is the standard for Kerberos, the use of RC4 can be a strong indicator of a Golden Ticket attack or other unauthorized ticket forging activities, as adversaries often force a downgrade to RC4 for easier offline cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects Microsoft Windows Event ID 4662 (Object Access) where specific GUIDs associated with sensitive Active Directory rights (specifically, those related to DCSync or sensitive extended rights) are accessed. The rule filters out events originating from Domain Controllers to identify potentially anomalous access patterns from non-DC endpoints.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to Windows Registry persistence locations (Run, RunOnce, Winlogon Shell/Userinit) where the assigned executable path is located within high-risk directories such as Temp, AppData, or Users Public folders. This is a common technique used by malware for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects instances of Kerberos Ticket-Granting Ticket (TGT) requests (Event IDs 4768 and 4769) that utilize the legacy RC4 encryption type (0x17). In modern Active Directory environments where AES is the standard for Kerberos, the use of RC4 can be a strong indicator of a Golden Ticket attack or other unauthorized ticket forging activities, as adversaries often force a downgrade to RC4 for easier offline cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects Microsoft Windows Event ID 4662 (Object Access) where specific GUIDs associated with sensitive Active Directory rights (specifically, those related to DCSync or sensitive extended rights) are accessed. The rule filters out events originating from Domain Controllers to identify potentially anomalous access patterns from non-DC endpoints.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to Windows Registry persistence locations (Run, RunOnce, Winlogon Shell/Userinit) where the assigned executable path is located within high-risk directories such as Temp, AppData, or Users Public folders. This is a common technique used by malware for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the loading of common Windows system DLLs (e.g., version.dll, dbghelp.dll) from suspicious, non-standard directory paths. Such behavior is often indicative of DLL side-loading or hijacking attempts, where an adversary places a malicious DLL with the same name as a legitimate one in a writable directory to influence application execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of native Windows binaries such as vssadmin.exe, wmic.exe, bcdedit.exe, and wbadmin.exe to inhibit system recovery by deleting shadow copies, clearing backup catalogs, or disabling automatic system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from non-reputable/non-Microsoft sources to suspicious directories such as Temp, AppData, or ProgramData, which is a common technique for ingress tool transfer during malware delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from non-reputable/non-Microsoft sources to suspicious directories such as Temp, AppData, or ProgramData, which is a common technique for ingress tool transfer during malware delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects suspicious activity associated with Cobalt Strike Beacon communication, specifically monitoring for known default named pipes and specific user-agent strings commonly used by Cobalt Strike in HTTP/S traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the initiation of a new process where the effective user context is SYSTEM, but the originating process was launched by a non-privileged user account. This behavior is indicative of token manipulation techniques such as token impersonation or theft (e.g., via DuplicateTokenEx or ImpersonateLoggedOnUser) to escalate privileges to SYSTEM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where an alert marked as process injection (T1055) involves an action process that is unsigned and differs from the actor process image, suggesting potential execution of an unauthorized or malicious payload masked by process injection techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects AWS CloudTrail and Azure Active Directory (Entra ID) privilege-escalation actions (e.g., attaching policies, creating access keys, adding roles) performed by principals from rare source IPs or associated with low-frequency administrative actions, indicating potentially compromised or unauthorized account activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the Sckit supply chain implant reading sensitive credential files from a user's home directory. The rule monitors processes spawned by Node.js or Python interpreters (the primary loaders for the Sckit worm) attempting to access high-value files like SSH keys, .npmrc, .pypirc, and various token storage files, indicating potential credential harvesting behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
104
Detects the abuse of Windows Management Instrumentation (WMI) to execute processes via wmic.exe or WmiPrvSE.exe, often combined with obfuscated command-line arguments such as encoded PowerShell or CMD commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000