Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects the abuse of signed Windows system binaries (LOLBins: certutil, mshta, regsvr32, rundll32, bitsadmin, msiexec) through the identification of command-line arguments that suggest malicious activity, such as downloading remote content, decoding files, executing scriptlets, or loading DLLs from temporary storage directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential DNS tunneling activity by analyzing DNS query logs for high entropy in subdomains, elevated volumes of TXT/NULL record types, and frequent NXDOMAIN responses. This pattern is characteristic of command-and-control (C2) or data exfiltration techniques using tools like dnscat2 or iodine, which encode data into DNS query labels.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell. The rule looks for command-line arguments referencing AMSI-related memory structures, methods, and DLLs such as AmsiUtils, AmsiScanBuffer, AmsiInitFailed, and amsi.dll. Bypassing AMSI is a common technique used by attackers to execute malicious scripts and deploy fileless payloads, such as Cobalt Strike or Sliver, while avoiding detection by endpoint security solutions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential container escape and privilege escalation attempts within a Kubernetes environment by monitoring for the creation of privileged pods, dangerous host mounts (such as /var/run/docker.sock or hostPath root mounts), and the use of escape-oriented utilities like nsenter or chroot, or access to the host's filesystem via /proc/1/root.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential Golden SAML activity by correlating Azure AD SAML sign-in events for privileged accounts with a lack of corresponding server-side ADFS authentication logs, unusual SAML issuer URIs, lack of on-premises authentication logs, or evidence of direct access to ADFS token-signing certificate private key material.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential DNS tunneling activities often associated with Command and Control (C2) communication. It monitors for anomalous patterns including excessively long DNS query labels, the use of uncommon DNS record types (TXT or NULL), and high volumes of DNS traffic directed towards specific domains. These behaviors are common indicators of data exfiltration or covert beaconing attempts designed to bypass traditional network security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of native Windows utilities such as vssadmin, wmic, wbadmin, and bcdedit used to delete volume shadow copies, the backup catalog, or disable system recovery boot policies. This activity is a common precursor to ransomware encryption to prevent data restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of token manipulation APIs (DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser), the 'runas' command for credential switching, or the execution of known security token manipulation tools (e.g., incognito, Tokenvator, Invoke-TokenManipulation). This activity is commonly associated with privilege escalation and token theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of data archival utilities (7zip, WinRAR) or command-line cloud synchronization tools (Rclone) to stage files in common temporary directories, immediately followed by network connections to known cloud storage endpoints. This pattern is characteristic of pre-encryption exfiltration activities often seen in ransomware campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects legitimate, signed executables from trusted system locations (e.g., System32) loading DLLs from non-standard, user-writable directories (e.g., Temp, AppData). This activity is a classic indicator of DLL side-loading, where an adversary places a malicious DLL in a directory to be picked up by a legitimate application, enabling the execution of malicious code under the context of a trusted process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects suspicious cross-process memory operations where a source process requests process creation/write permissions on a target process (e.g., browsers, explorer.exe, or svchost.exe), followed immediately by the execution of a remote thread injection technique such as CreateRemoteThread, QueueUserAPC, or NtCreateThreadEx within the same process pair.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects multiple inbound HTTP requests targeting known vulnerable application paths (e.g., cgi-bin, .env files, actuator gateways, path traversal, WordPress plugins, PHP eval files, and various server administration consoles) from a single source within a short timeframe. This behavior is indicative of an automated scanner or exploit chain attempting to identify and compromise public-facing applications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects high-volume DNS traffic characterized by long, high-entropy subdomain labels, which are often used as a mechanism for command-and-control (C2) communication or data exfiltration via DNS tunneling.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects HTTP POST requests directed to OpenAI or Anthropic API endpoints originating from non-browser user agents (e.g., Python requests, curl, Go-http-client). This activity may indicate automated interactions, potentially for malicious purposes such as script-based interaction with LLMs or unauthorized API usage.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects repeated, small outbound HTTP/HTTPS requests to an external destination, a behavior characteristic of scripted command-and-control (C2) beaconing where a client periodically polls a server for instructions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects large HTTP POST requests (exceeding 100KB) directed to public LLM API endpoints such as OpenAI or Anthropic. This behavior may indicate potential bulk data exfiltration or unauthorized sharing of sensitive data with external AI providers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects multiple attempts to connect to administrative shares (ADMIN$, C$, IPC$) from a single source within a 60-second window. This pattern is indicative of automated lateral movement or enumeration attempts using the SMB protocol.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
104
Detects the use of the built-in Windows utility rundll32.exe to execute the MiniDump functionality within comsvcs.dll against the Local Security Authority Subsystem Service (LSASS). This technique is a common method for attackers to bypass signature-based security tools and obtain sensitive credentials from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
604
Detects the abuse of the legitimate Windows system binaries regsvr32.exe and rundll32.exe to execute remote scripts or scriptlets, a technique often used to bypass application control and proxy execution of malicious code (similar to Squiblydoo).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000