Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects Kerberos ticket requests (AS-REQ/TGS-REQ) that exhibit characteristics of a forged Golden Ticket, specifically the use of legacy RC4 (0x17) encryption in environments where AES is typically preferred, non-standard ticket options (0x40810000), and requests for accounts or services that lack a corresponding legitimate authentication event. This detection aims to identify the post-compromise phase where an adversary uses a forged TGT to impersonate domain accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the use of native Windows utilities such as vssadmin, ntdsutil, or diskshadow to create volume shadow copies for the purpose of accessing or extracting the ntds.dit Active Directory database file. This activity is a common indicator of credential theft attempts where adversaries bypass file access protections to offline-process the database and retrieve password hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized access attempts to SYSTEM-level processes (winlogon.exe, services.exe) using specific access rights such as PROCESS_DUP_HANDLE or PROCESS_QUERY_INFORMATION. This behavior is indicative of token stealing or impersonation attempts often utilized by tools like JuicyPotato, RoguePotato, and PrintSpoofer to escalate privileges to SYSTEM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a sequence of multiple RDP authentication failures (Event ID 4625, Logon Type 10) from a specific source IP, followed by a successful RDP authentication (Event ID 4624, Logon Type 10) from the same source IP. This pattern indicates a successful credential brute force or password spraying attack against RDP, which is a common initial access vector for ransomware and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects potential process injection attempts where a browser or Office application attempts to write to the memory or create a remote thread within high-value or trusted system processes like svchost.exe or explorer.exe. This activity is indicative of defense evasion techniques such as DLL or PE injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects suspicious process access to the Local Security Authority Subsystem Service (lsass.exe) with access masks commonly associated with credential dumping techniques. The rule specifically monitors for high-privileged access requests by unauthorized processes, excluding known legitimate tools and system services, to identify attempts to extract cached authentication materials such as NTLM hashes or Kerberos tickets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects PowerShell processes (including pwsh and ISE) referencing Anti-Malware Scan Interface (AMSI) related classes and methods in their command line arguments. This is a common indicator of an attempt to interact with or manipulate AMSI, often used to bypass or disable security scanning during the execution of malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation or connection of named pipes that match known default and common malleable C2 profile patterns used by the Cobalt Strike post-exploitation framework. These named pipes are frequently utilized by Cobalt Strike beacons for inter-process communication, SMB/TCP beacon functionality, and staging during post-exploitation activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects PowerShell processes (including pwsh and ISE) referencing Anti-Malware Scan Interface (AMSI) related classes and methods in their command line arguments. This is a common indicator of an attempt to interact with or manipulate AMSI, often used to bypass or disable security scanning during the execution of malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects instances where the WMI service (wmiprvse.exe) spawns common command-line or system tools such as cmd.exe, powershell.exe, or rundll32.exe. This behavior is often indicative of lateral movement or remote command execution via WMI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects common suspicious PowerShell command-line patterns often used for malicious purposes, including base64-encoded command execution, hidden-window execution with common evasion flags, and the use of download/execution cmdlets for in-memory payload delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects potential lateral movement by identifying a single user account authenticating to three or more distinct hosts using NTLM via network (LogonType 3) or impersonation (LogonType 9) logons, which is characteristic of credential-based movement across a network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule monitors for an abnormally high number of Kerberos Ticket Granting Service (TGS) requests using the RC4-HMAC encryption type (0x17) from a single IP address to various service accounts. This pattern is indicative of Kerberoasting, a technique where attackers attempt to obtain service tickets to crack service account passwords offline.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys that point to executables or scripts located within suspicious user-writable directories such as AppData, Temp, or Users Public. This is a common technique used by adversaries to establish persistence on a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects attempts to disable, modify, or stop security software and endpoint protection services. The rule monitors for registry changes to Windows Defender settings, manual service management commands (sc, net) targeting security processes, and PowerShell execution using 'Set-MpPreference' to disable protection features.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects instances where a process attempts to access the memory of the Local Security Authority Subsystem Service (LSASS.exe) with suspicious access rights often associated with credential dumping. The rule excludes known benign processes such as antivirus and debugging tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Kerberos TGS requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting. By monitoring Event IDs 4768 and 4769 for this specific encryption type, this rule identifies potential attempts to offline-crack service account passwords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of known Windows system binaries (rundll32, regsvr32, mshta, msiexec) with command-line arguments indicative of proxy execution or script-based attacks. The rule identifies patterns commonly associated with downloading or executing remote payloads, including the use of URLs, JavaScript, VBScript, or specific DLL exports designed to execute code indirectly or from a remote source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Microsoft Office applications (Word, Excel, Outlook, PowerPoint) spawning common LOLBins or command-line interpreters. This behavior is frequently associated with malicious macros or exploitation attempts delivering secondary payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation or modification of scheduled tasks that exhibit suspicious characteristics, such as using common temporary directories, executing PowerShell with encoded commands, running tasks as SYSTEM, or using tasks that attempt to hide by using unusual naming conventions. These techniques are often used by adversaries to establish persistence or facilitate execution in a stealthy manner.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous DNS queries that utilize long labels or non-standard record types (TXT, NULL, CNAME) which are frequently associated with DNS tunneling and command-and-control communication. The rule flags endpoints with a high volume of these suspicious requests or exceptionally long domain labels.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000