Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects the creation or modification of Google Cloud Config Connector (KCC) IAM resources (IAMPolicyMember, IAMPartialPolicy, IAMPolicy) that assign high-privilege roles like 'roles/owner' or 'roles/resourcemanager.organizationAdmin'. This monitors for potential privilege escalation where a low-privilege actor leverages the KCC controller's high-privilege service account to perform unauthorized IAM binding changes on Google Cloud resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
004
Detects the creation of suspicious scheduled tasks using the Windows schtasks.exe utility. The rule flags tasks that are configured to run as SYSTEM, include PowerShell encoded commands, or target directories commonly used for persistence such as Temp, AppData, or Public.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the abuse of built-in Windows binaries 'regsvr32.exe' and 'msbuild.exe' for proxy execution. Specifically, it flags 'regsvr32.exe' loading remote scriptlets via HTTP and 'msbuild.exe' processing project files containing inline tasks, which are common techniques used to execute arbitrary malicious code while bypassing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential persistence mechanisms involving the creation of 'Locked' registry keys within Software\Classes and subsequent use of Run registry keys that reference 'Locked://' URIs. It also identifies suspicious execution of rundll32.exe utilizing specific CLSID-based command line arguments associated with the '{CFDC57BA-1705-45AF-BA10-EFC3D592982B}' identifier, often linked to malicious activity patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
204
Detects the creation of suspicious scheduled tasks using the Windows schtasks.exe utility. The rule flags tasks that are configured to run as SYSTEM, include PowerShell encoded commands, or target directories commonly used for persistence such as Temp, AppData, or Public.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects attempts by an attacker to disable or modify Windows security software and features. It monitors for three distinct behaviors: execution of 'Set-MpPreference' to modify Windows Defender settings (exclusions or real-time monitoring), execution of 'sc.exe' to stop security-related services (such as EDR or AV services), and direct modification of Windows registry keys to disable Windows Defender components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the abuse of Windows Management Instrumentation (WMI) to execute processes via wmic.exe or WmiPrvSE.exe, often combined with obfuscated command-line arguments such as encoded PowerShell or CMD commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized processes (other than known browsers like Chrome, Edge, or Firefox) attempting to access sensitive browser files such as 'Login Data', 'Cookies', or 'Web Data'. This behavior is commonly associated with credential stealing or browser session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects OAuth token requests associated with the 'PDF Identity Verifier' application or specific client IDs, often used by malicious browser extensions or phishing applications to exfiltrate sensitive Google account data, specifically Gmail and user profile information.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
103
Detects suspicious modifications to Windows Registry keys associated with URL protocol handlers or automatic startup mechanisms. Adversaries often use custom URL schemes or registry run keys to maintain persistence or execute malicious code when a specific protocol is invoked or upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
004
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) using either the built-in 'comsvcs.dll' library via 'rundll32.exe' or by requesting specific sensitive process access rights to 'lsass.exe' from unauthorized processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects user-initiated execution of scripts or binaries directly from the root of a drive letter. This pattern is commonly associated with phishing campaigns delivering malicious payloads via mounted ISO or IMG files, which allow attackers to bypass mark-of-the-web or macro security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the installation or execution of common remote access tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop) using silent or unattended installation flags. This rule explicitly excludes activity originating from known administrative and management platforms such as Microsoft Intune and SCCM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where rundll32.exe loads a DLL file named Use.dll from a subdirectory named 'ComponentsFolder' within the AppData directory. This pattern is indicative of sandbox evasion techniques used by malware, such as the DarkMe RAT, where the DLL acts as an anti-sandbox gateway to check the execution environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
004
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) using either the built-in 'comsvcs.dll' library via 'rundll32.exe' or by requesting specific sensitive process access rights to 'lsass.exe' from unauthorized processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects user-initiated execution of scripts or binaries directly from the root of a drive letter. This pattern is commonly associated with phishing campaigns delivering malicious payloads via mounted ISO or IMG files, which allow attackers to bypass mark-of-the-web or macro security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the installation or execution of common remote access tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop) using silent or unattended installation flags. This rule explicitly excludes activity originating from known administrative and management platforms such as Microsoft Intune and SCCM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects high-risk AWS API calls that are commonly associated with privilege escalation and persistence. It monitors for the creation of overly permissive IAM policies (wildcard permissions), the creation of new access keys for existing users, and suspicious AssumeRole operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of legitimate Windows binaries (certutil.exe and bitsadmin.exe) to download files from remote URLs to sensitive or common staging directories (Temp, AppData, ProgramData). Attackers frequently abuse these built-in tools for 'living off the land' (LotL) to retrieve malicious payloads or secondary tools while bypassing traditional signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects attempts to steal the Active Directory database (ntds.dit) and associated security files by creating volume shadow copies using native Windows utilities like ntdsutil, vssadmin, or wmic. It also monitors for direct file system access or creation attempts related to these sensitive database files within shadow copy paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects persistence attempts on Windows by monitoring for modifications to common Registry Run/RunOnce keys or the creation of executable files within the user startup directory. The rule excludes common legitimate processes like msiexec.exe, trustedinstaller.exe, and explorer.exe to minimize false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000