Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects modifications to the 'PlugPlay' Windows service using 'sc.exe', specifically involving changes to the binary path (binpath) and subsequent service status changes (start/stop) within a short timeframe (30 minutes). This behavior is often associated with the persistence or hijacking of services to execute malicious files, specifically targeting Microsoft Office or Copilot-related process names.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects anomalous file activity associated with the PaperCut application (pc-app.exe), characterized by the creation of numbered binary chunks (.bin) followed by the creation of a status log file (pcxboot_l.txt) and the subsequent deletion of the binary chunks. This behavior is indicative of an in-memory Java payload loader pattern used to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects credential-dumping modules (such as nanodump, hashdump, and lsadump variants) associated with AdaptixC2 framework being invoked or used by the 'mscopilot.exe' process. The rule monitors for command-line arguments indicating credential extraction, unauthorized attempts to open handle to lsass.exe, and access to sensitive registry hives (SAM, Security, LSA) by the suspect process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects the deletion, truncation, or modification of critical PaperCut server logs and application files (server.log, pcxboot_l.txt, .bin files). This activity is associated with attempts to conceal exploitation of PaperCut vulnerabilities (e.g., CVE-2026-82078/81578) by clearing logs or tampering with binaries, typically executed by the PaperCut application processes themselves (pc-app.exe or Java runtime).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
This rule detects suspicious activity originating from the PaperCut 'pc-app.exe' process. It monitors for the creation or execution of a file named 'mscopilot.exe' within the non-standard directory 'C:\Microsoft.Office365\'. The rule matches based on a known malicious SHA1 hash or the specific file-write-then-execute behavior within a one-hour window, indicating potential AdaptixC2 loader activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects network traffic associated with Adversary-in-the-Middle (AiTM) phishing kits that impersonate Microsoft and Google login pages. The rules identify the presence of specific HTML elements (like Cloudflare Turnstile anti-bot gates) and authentication session cookie headers served from non-authorized/non-official domains, indicating a reverse-proxy phishing attack.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects network traffic associated with Adversary-in-the-Middle (AiTM) phishing kits that impersonate Microsoft and Google login pages. The rules identify the presence of specific HTML elements (like Cloudflare Turnstile anti-bot gates) and authentication session cookie headers served from non-authorized/non-official domains, indicating a reverse-proxy phishing attack.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects potential poisoning of an AI agent's RAG knowledge base or vector store through suspicious bulk ingestion or injection of imperative instruction-style content. The rule correlates these ingestion events with subsequent anomalous tool usage patterns by the same agent session, indicating a possible prompt injection or data manipulation attack aimed at altering agent behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects potential poisoning of an AI agent's RAG knowledge base or vector store through suspicious bulk ingestion or injection of imperative instruction-style content. The rule correlates these ingestion events with subsequent anomalous tool usage patterns by the same agent session, indicating a possible prompt injection or data manipulation attack aimed at altering agent behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects instances where the WMI Provider Host (wmiprvse.exe) spawns suspicious child processes such as cmd.exe, powershell.exe, or rundll32.exe, which are correlated with inbound network connections on ports 135 (RPC/DCOM) or 445 (SMB). This behavior is characteristic of lateral movement techniques used by tools like Impacket's wmiexec.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (lsass.exe) with sensitive access rights (e.g., PROCESS_VM_READ, PROCESS_QUERY_INFORMATION). These access patterns are frequently utilized by credential dumping tools like Mimikatz, ProcDump, or malicious abuse of system utilities to extract plaintext passwords or NTLM hashes from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of PowerShell or PWSH with encoded command flags (-EncodedCommand, -enc, -e), which is a common technique used by adversaries to hide malicious scripts or payloads from inspection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000