Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule identifies potential RDP-based lateral movement by detecting when a single user account successfully authenticates to multiple distinct hosts using LogonType 10 (RemoteInteractive) within a 1-hour time window. A threshold of three or more distinct hosts is used to flag activity that deviates from typical single-host RDP usage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects the use of legitimate Windows binaries (LOLBins) certutil.exe and bitsadmin.exe for suspicious activities such as downloading files via URL or decoding encoded files. This rule explicitly excludes known legitimate administrative activity originating from Microsoft Configuration Manager (SCCM).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects the initialization of cloud synchronization tools like rclone or MEGAsync, accompanied by the creation of configuration files and subsequent high-volume network activity directed toward common cloud storage providers, indicative of unauthorized data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects execution of rundll32.exe and regsvr32.exe with command lines indicative of living-off-the-land techniques, including usage of remote scriptlets, URLs, JavaScript, and execution from non-standard system paths, which are often used for proxy execution or to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the creation of Windows scheduled tasks that include suspicious interpreters (PowerShell, cmd.exe, rundll32) or execution paths located in common attacker-writable directories (Temp, AppData, ProgramData), which is a common technique for persistence and command-and-control re-establishment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects a single user account performing an unusually high volume of Kerberos Service Ticket (TGS) requests (Event ID 4769) within a short window, specifically using RC4 encryption (0x17). This behavior is highly characteristic of Kerberoasting, where attackers request tickets for various service principal names (SPNs) to perform offline password cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects persistence attempts by monitoring modifications to Windows registry run keys (Run, RunOnce, Winlogon Shell/Userinit) or file creation within the Startup folder. It alerts when these locations are updated to reference suspicious file paths (Temp/AppData) or execute scripts (vbs, ps1, js, wsf, bat, hta).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects network connections originating from or connecting to hosts that utilize known Cobalt Strike default JA3 or JA3S TLS fingerprints. These fingerprints are indicative of Cobalt Strike's default beacon communication patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that point to suspicious script execution, encoded commands, or files located in commonly abused writable directories like Temp or ProgramData. This behavior is indicative of potential persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that point to suspicious script execution, encoded commands, or files located in commonly abused writable directories like Temp or ProgramData. This behavior is indicative of potential persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects the abuse of the Windows Background Intelligent Transfer Service (BITS) via the bitsadmin command-line tool or PowerShell's Start-BitsTransfer to download files (such as .exe, .dll, or .ps1) or facilitate potential persistence. Adversaries use these methods to transfer malicious payloads stealthily in the background or to maintain persistence on a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the loading of known-vulnerable signed drivers typically associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. These drivers are frequently abused to gain kernel-mode privileges, allowing attackers to disable or terminate EDR, antivirus, and other security processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
17 days ago
102
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
17 days ago
102
Detects the execution of PowerShell with suspicious command-line arguments often used by adversaries for obfuscation, evasion, or in-memory code execution, such as encoded commands, hidden windows, and downloading external content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
This rule detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos Service Ticket (TGS) requests (event ID 4769) for non-machine service accounts, specifically focusing on tickets encrypted with RC4 (etype 23). A high count of ticket requests or distinct Service Principal Names (SPNs) requested by a single client in a short period is characteristic of an adversary attempting to harvest hashes for offline cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the creation of scheduled tasks using schtasks.exe that either trigger on user logon or startup and point to common writable directories (e.g., Temp, AppData), or tasks created with a remote system argument, which is frequently used by adversaries for persistence or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
201
This rule detects the use of native Windows utilities certutil.exe and bitsadmin.exe for potentially malicious purposes. Specifically, it flags certutil.exe being used for decoding or cached URL operations, and bitsadmin.exe being used to initiate file transfers from remote URLs or network paths. These tools are commonly abused by attackers for file staging, ingress tool transfer, and deobfuscation of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
This rule detects the creation of named pipes with names patterns commonly associated with post-exploitation frameworks, such as Cobalt Strike and Sliver. These frameworks frequently use specific, sometimes randomized, pipe patterns for inter-process communication, lateral movement, or command and control (C2) operations. Monitoring these pipe names can help identify malicious activity occurring within a compromised environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
001
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
001
Page 172 of 1871