Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances of explorer.exe being launched by a parent process other than expected system processes (explorer.exe, userinit.exe, or winlogon.exe). This behavior is highly irregular for Windows desktop environments and may indicate process injection or malicious process masquerading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
203
Detects instances where npm processes (install, preinstall, or postinstall) spawn suspicious child processes such as shell interpreters (cmd, powershell, bash, sh), network utilities (curl, wget), or scripting interpreters (python). This behavior is often associated with malicious npm package installation or software supply chain compromise where post-install scripts are used to gain persistence or download secondary payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of PowerShell with hidden window arguments from explorer.exe, typically indicative of ClickFix social engineering where a user is tricked into pasting malicious commands into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
303
Detects instances where processes (excluding known legitimate .NET processes) load common .NET runtime modules (e.g., clr.dll, mscoree.dll) followed by remote process injection or handle-based process access, which is often indicative of reflective assembly loading used by loaders like PIVOTPIPE to execute malicious code within a target process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects a Node.js server process (e.g. "next-server", "node.exe") spawning
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
22 days ago
007
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
203
This rule detects unauthorized attempts to perform a DCSync attack by monitoring for Active Directory Event ID 4662. It triggers when an account that is not a recognized domain controller (which typically end with a '$' sign) successfully requests replication data using the Directory Replication Service (DRS) GetNCChanges rights. This behavior is a common indicator of credential dumping via tools like Mimikatz.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the execution of known privilege escalation tools and the use of specific Windows privilege keywords (such as SeImpersonatePrivilege) often associated with access token manipulation and token impersonation attacks to elevate privileges to SYSTEM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects instances where rundll32.exe is executed with suspicious command-line parameters that are often associated with malicious activity. This includes attempts to dump memory (comsvcs.dll), utilize specific protocols (url.dll), execute JavaScript, or leverage common writeable directories for payload staging, all of which are common techniques used by attackers to proxy execution and evade defenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects attempts to disable Windows Defender features via PowerShell, terminate critical security services using administrative tools like sc.exe or net.exe, or inject/patch AMSI (Antimalware Scan Interface) within a process context to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
This rule detects Terraform CLI activity interacting with suspicious domains or modules, specifically targeting known repositories or namespaces (e.g., gocommunity.io, gogets.dev). It monitors for Terraform initialization or application patterns referencing these domains in process command lines, as well as the creation of Terraform provider files within these specific namespaces. This behavior is indicative of potential supply chain compromise involving malicious Terraform modules or dependencies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
201
Detects the execution of 'go' or 'go.exe' with 'run' commands originating from infrastructure automation or orchestration tools such as Terraform, Docker, or other related automation processes. This pattern may indicate the execution of arbitrary Go code or modules in environments where infrastructure code is being managed or deployed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects the execution of terraform.exe or go.exe on developer hosts, which acts as a precursor to the malicious Terraform provider campaign (Graphalgo) that targets cloud credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects suspicious activities associated with ysoserial.net gadget chain exploitation targeting SharePoint's w3wp.exe process. The rule correlates the loading of specific .NET assemblies (PresentationFramework, System.Xaml, System.Data.Services) with the subsequent execution of command shells (cmd, powershell) or the presence of common ysoserial.net-related strings (ActivitySurrogateSelector, LosFormatter) within command lines originating from the w3wp.exe process, indicating a potential web shell.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
002
Detects the execution of the Graphalgo RAT second-stage payload. The rule identifies the spawning of a detached 'go run .' process, which performs an ephemeral key exchange using a hardcoded public key before C2 establishment. It also correlates this activity with parent processes common in software build environments (npm, terraform, go) to differentiate malicious staging from developer activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects network connection attempts to 'third-party.com', which was historically a common documentation placeholder domain but has since been acquired by attackers to serve malicious infrastructure. This rule flags processes interacting with this domain, identifying potential exploitation via copy-pasted code or documentation examples.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects the execution of the C# compiler (csc.exe) initiated by PowerShell. This behavior is often indicative of in-memory compilation and execution of malicious code, bypassing traditional file-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
106
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
000
This rule detects unauthorized attempts to extract credentials from the Local Security Authority Subsystem Service (LSASS) process. It monitors for two distinct techniques: non-standard processes opening handles to lsass.exe with sensitive access rights (credential-dumping) and the use of rundll32.exe to invoke the MiniDump function within comsvcs.dll against lsass.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects directory replication requests (Event ID 4662) using DS-Replication-Get-Changes or DS-Replication-Get-Changes-All GUIDs initiated by a computer account that is not a recognized domain controller. This behavior is indicative of a DCSync attack, where an adversary attempts to pull sensitive credential data directly from Active Directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects anomalous Kerberos ticket requests that are characteristic of Golden Ticket attacks. The rule flags the use of weak encryption types (e.g., RC4) commonly used in forged tickets even in AES-enforced environments, and direct requests for the KRBTGT service account outside of legitimate ticket renewal operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Page 171 of 1871