Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects multiple reconnaissance commands executed by PowerShell processes running as the SYSTEM account. This behavior is indicative of an attacker attempting to enumerate domain trusts, group memberships, or user sessions on a host to facilitate lateral movement or privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
303
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects the execution of 'LevelInstaller.exe' with specific installation arguments ('--action install --force --key') in conjunction with the presence of the 'level.exe' binary in its designated Program Files directory. The rule optionally identifies related scheduled task creation for 'Level Watchdog' and network activity associated with the 'level.io' domain or specific IP address.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
303
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
104
Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000