Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of the Windows built-in utility mshta.exe when it is used to load remote HTA files or scripts via HTTP/HTTPS URLs, or when it is directly spawned by Microsoft Office applications (Word/Excel). This behavior is characteristic of malicious document macros or phishing-based initial access where mshta is used as a proxy to execute code and evade security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the loading or service registration of known vulnerable or malicious signed drivers commonly used in Bring Your Own Vulnerable Driver (BYOVD) attacks. These drivers are leveraged by adversaries to gain kernel-level privileges, bypass security controls, and terminate endpoint protection agents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
101
Detects the use of bitsadmin.exe to initiate file transfers from remote URLs to sensitive or writable system directories, or the use of /SetNotifyCmdLine to define a command to execute upon job completion. These techniques are often used by adversaries to download payloads or establish persistence via BITS jobs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects execution of the Microsoft Connection Manager Profile Installer (cmstp.exe) with suspicious command-line parameters (using remote INF files via UNC or HTTP) or when it spawns unexpected child processes, both of which are indicative of potential bypass of User Account Control (UAC) or security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the execution of diskshadow.exe with the /s (scripted) flag, followed by file access to sensitive Windows credential files (ntds.dit or SAM). This behavior indicates the abuse of the Windows Diskshadow utility to create a volume shadow copy for the purpose of offline credential exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the invocation of Windows Subsystem for Linux (WSL) binaries (wsl.exe or wslconfig.exe) using command-line arguments that enable arbitrary command execution, such as -e, --exec, or shell interpreters (bash -c, sh -c), or web-based retrieval tools like curl/wget. This technique is often used to execute commands or download payloads within a Linux environment on Windows, potentially bypassing security controls focused on native Windows processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
This rule detects potentially suspicious activity involving conhost.exe, a process typically associated with console applications. It identifies conhost.exe instances running from suspicious paths (e.g., Temp, Downloads, AppData) or launched by unexpected parent processes. Additionally, it detects scenarios where conhost.exe acts as the parent process to common command-line or scripting utilities, which is an atypical behavior often indicative of an attempt to obscure malicious command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
This rule detects potential 'Squiblydoo' attacks where regsvr32.exe is used to execute remote scriptlets via HTTP/HTTPS or loads the 'scrobj.dll' library in an unusual manner, such as without a local DLL file path, which is a common indicator of bypassing application allowlisting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
000
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
000
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
000
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
000
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
001
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
000
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
000
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
101
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
101
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
101
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
000
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
000
Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
001
Page 176 of 1871