Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects persistence attempts on Windows by monitoring for modifications to common Registry Run/RunOnce keys or the creation of executable files within the user startup directory. The rule excludes common legitimate processes like msiexec.exe, trustedinstaller.exe, and explorer.exe to minimize false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects attempts to clear or delete Windows Event Logs using common utilities like wevtutil.exe, PowerShell cmdlets, or direct file system deletion of .evtx files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where an unauthorized or non-standard source process performs cross-process access (such as OpenProcess or similar operations indicative of code injection techniques like CreateRemoteThread or QueueUserAPC) against a sensitive target host process, such as explorer.exe, svchost.exe, or notepad.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility with either system-level privileges ('/ru SYSTEM') or persistent triggers ('/sc onlogon' or '/sc onstart'). The rule filters out commonly trusted parent processes, highlighting potential persistence mechanisms established by unauthorized or unusual processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous lateral movement behavior where a single user account authenticates via NTLM (LogonType 3, network logon) to three or more distinct hosts within a 30-minute window, without a preceding interactive logon (LogonType 2). This pattern is a strong indicator of an adversary using captured NTLM hashes to move laterally across a Windows environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of rundll32.exe to invoke the MiniDump function of comsvcs.dll targeting the lsass.exe process. This technique is a well-known living-off-the-land (LotL) method used by adversaries to create a memory dump of LSASS, which can then be exfiltrated and analyzed offline using tools like Mimikatz to extract credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects successful authentication attempts by the same user account from two different geographic locations within a timeframe that is physically impossible to travel between. This detection often highlights compromised accounts or session token theft, including scenarios where MFA mechanisms have been bypassed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the deletion of volume shadow copies using common Windows administrative tools such as vssadmin, wmic, and PowerShell. This activity is frequently observed during the pre-encryption stage of ransomware attacks to prevent system restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of msbuild.exe targeting project files (.csproj, .proj, .xml) located in user-writable directories such as Temp or Downloads, or containing command-line indicators of inline C# task execution (e.g., UsingTask, CodeTaskFactory). This behavior is commonly used for proxy execution and bypassing application allow-listing via LOLBAS.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects Active Directory Certificate Services (AD CS) enrollment events (4886/4887) where a request includes an enrollee-supplied Subject Alternative Name (SAN). This behavior is characteristic of ESC1 certificate template abuse (e.g., using tools like Certipy or Certify) to request certificates that impersonate other users or machine accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of named pipes associated with default Cobalt Strike malleable profiles and common open-source C2 frameworks (e.g., Sliver, Havoc) via EDR pipe-creation telemetry. These pipes are frequently used for SMB beacon communication within compromised networks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of named pipes associated with default Cobalt Strike malleable profiles and common open-source C2 frameworks (e.g., Sliver, Havoc) via EDR pipe-creation telemetry. These pipes are frequently used for SMB beacon communication within compromised networks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects 'kubectl exec' or 'kubectl attach' requests targeting pods configured with dangerous security contexts (privileged, hostPID, or hostNetwork). The rule filters out known CI/CD service accounts to focus on potentially malicious manual or unauthorized programmatic access, which often serves as a precursor to container breakout or host-level compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous DNS traffic patterns where a single client host performs a high volume of TXT or NULL DNS queries containing long, high-entropy subdomain labels directed at a small set of domains. This behavior is indicative of DNS tunneling, frequently used for covert Command and Control (C2) communication or data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects execution of Mimikatz or usage of its specific command-line arguments (such as sekurlsa or lsadump modules) which indicate attempted credential dumping from system memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
003
Detects the request for DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights on domain objects, which are highly sensitive Active Directory permissions required to perform DCSync attacks to harvest credentials from Domain Controllers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized modifications to Windows Registry Run/RunOnce keys or the Startup folder. The rule specifically targets persistence attempts where the associated process resides in suspicious directories (Temp, AppData) or uses command-line arguments indicative of script execution (powershell, wscript, mshta, encoded commands, or script extensions). It excludes known legitimate installer behavior involving msiexec or setup processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects WmiPrvSE.exe spawning child processes within 120 seconds of a Type 3 (Network) logon event. This behavior is a common indicator of remote command execution, frequently used by lateral movement tools like Impacket's wmiexec or similar WMI-based remote execution frameworks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests using the weak RC4 encryption type (0x17) from a single account within a 5-minute window. It excludes machine accounts and common system service requests to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects suspicious NTLM network logon events (Logon Type 3) involving privileged accounts that do not have corresponding Kerberos authentication events (4768/4769) in the preceding hour. The detection specifically triggers when a single account logs into two or more distinct hosts within a 15-minute window, which is indicative of lateral movement using compromised credentials or Pass-the-Hash techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000