Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects the use of EfsRpcOpenFileRaw (opnum 0) against the EFSRPC interface. This specific function is abused by the PetitPotam exploit to coerce a Windows machine, typically a domain controller, into authenticating to an attacker-controlled host via NTLM. This forced authentication is a precursor to NTLM relay attacks such as those targeting Active Directory Certificate Services (AD CS).
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
20 days ago
104
Detects potential ClickFix-style social engineering attacks where a victim is prompted to execute an encoded PowerShell command (often via copy-paste into a terminal). The rule specifically monitors PowerShell processes initiated by shell environments (explorer.exe, cmd.exe, or WindowsTerminal.exe) that execute encoded, hidden scripts to perform multiple suspicious network requests for files (e.g., .zip, .enc, .bin) from non-standard domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
308
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
4113
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
003
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
003
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
003
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
003
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
003
Detects evidence of the Rapuncel infostealer attempting to compromise Chrome or Edge browsers. The rule identifies suspicious image loads into browser processes linked to known malicious hashes or the creation of specific browser decryption log files used by the malware to defeat App-Bound encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects instances where Microsoft Visual Studio Code (Code.exe) spawns common interpreters or command-line tools (such as node, python, cmd, or powershell) that are not associated with known internal VS Code process behaviors like renderer tasks or tunnel operations. This activity may indicate malicious use of the integrated terminal or extension execution contexts to execute unauthorized code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the modification of Windows Registry Run keys that point to suspicious executable paths or known naming patterns associated with specific services (SMQDService and winappx) often utilized for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the creation or modification of registry entries within the 'HKCU\...\Run' hive that point to executables located in suspicious or atypical directories such as 'ProgramData', 'Users\All Users', or specific non-standard application paths often used by malware for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects instances where a desktop messaging application (WhatsApp or Telegram) spawns a child process that matches known suspicious naming conventions or lure keywords, suggesting that a user has executed a malicious file shared via the platform.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the execution of binaries masquerading as legitimate software (such as KeePass, Adobe Flash, or specialized medical document viewers) from user-writable and non-standard execution paths (e.g., Downloads, Temp). This behavior is characteristic of the CHOSEN BRICK malware's lure-execution stage, where users are socially engineered into running a decoy installer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the use of built-in Windows utilities and commands to disable system recovery features, delete volume shadow copies, clear backup catalogs, or perform mass file deletion. This behavior is highly indicative of wiper malware preparing for a destructive attack by preventing system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
002
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
002
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
002
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
002
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
002
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
002
Page 179 of 1871