Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys that point to executables or scripts located within suspicious user-writable directories such as AppData, Temp, or Users Public. This is a common technique used by adversaries to establish persistence on a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects attempts to disable, modify, or stop security software and endpoint protection services. The rule monitors for registry changes to Windows Defender settings, manual service management commands (sc, net) targeting security processes, and PowerShell execution using 'Set-MpPreference' to disable protection features.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects instances where a process attempts to access the memory of the Local Security Authority Subsystem Service (LSASS.exe) with suspicious access rights often associated with credential dumping. The rule excludes known benign processes such as antivirus and debugging tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Kerberos TGS requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting. By monitoring Event IDs 4768 and 4769 for this specific encryption type, this rule identifies potential attempts to offline-crack service account passwords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of known Windows system binaries (rundll32, regsvr32, mshta, msiexec) with command-line arguments indicative of proxy execution or script-based attacks. The rule identifies patterns commonly associated with downloading or executing remote payloads, including the use of URLs, JavaScript, VBScript, or specific DLL exports designed to execute code indirectly or from a remote source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Microsoft Office applications (Word, Excel, Outlook, PowerPoint) spawning common LOLBins or command-line interpreters. This behavior is frequently associated with malicious macros or exploitation attempts delivering secondary payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation or modification of scheduled tasks that exhibit suspicious characteristics, such as using common temporary directories, executing PowerShell with encoded commands, running tasks as SYSTEM, or using tasks that attempt to hide by using unusual naming conventions. These techniques are often used by adversaries to establish persistence or facilitate execution in a stealthy manner.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous DNS queries that utilize long labels or non-standard record types (TXT, NULL, CNAME) which are frequently associated with DNS tunneling and command-and-control communication. The rule flags endpoints with a high volume of these suspicious requests or exceptionally long domain labels.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the invocation of Active Directory replication rights by monitoring Event 4662 for specific directory service replication GUIDs (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All). This behavior is characteristic of adversary techniques such as DCSync used by tools like Mimikatz lsadump::dcsync or Impacket secretsdump to extract domain password hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects potential C2 beaconing activity by identifying repeated network connections to the same external host that exhibit consistent payload sizes (low variance) and frequency, or by flagging HTTP requests containing default URI patterns associated with Cobalt Strike profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects a credential-based attack where a single source IP performs multiple failed RDP (LogonType 3/10) attempts against various user accounts, followed by a successful authentication from the same source within an hour. This pattern is indicative of password spraying or brute-forcing followed by successful lateral movement via Remote Desktop.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Sysmon Event ID 10 (ProcessAccess) events where a process opens lsass.exe with a GrantedAccess mask matching known credential-dumping access rights (e.g. PROCESS_VM_READ combinations used by Mimikatz/ProcDump-style tooling), excluding common legitimate EDR/AV/diagnostic source processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule monitors for process creation events where the parent process is identified as the WMI Provider Host (wmiprvse.exe) or the Windows Management Instrumentation Command-line (wmic.exe) tool, executing a Win32_Process creation command. This pattern is commonly used by adversaries for remote execution and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects potential Kerberoasting activity by identifying anomalous behavior where a single account requests 5 or more unique Kerberos Service Principal Name (SPN) tickets within a 5-minute window, excluding common service accounts and krbtgt ticket requests. This behavior is indicative of an attacker attempting to enumerate and obtain tickets for multiple services for offline brute-force password cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in PowerShell by monitoring for common bypass techniques such as reflective loading of AmsiUtils, tampering with the amsiInitFailed field, or memory patching of AmsiScanBuffer via Script Block Logging (EventID 4104).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized Active Directory replication requests (DCSync) by monitoring Event ID 4662 for specific directory replication GUIDs originating from computers not identified as domain controllers or by accounts not pre-approved for replication tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of scheduled tasks using schtasks.exe or Event ID 4698 that involve scripting interpreters (powershell, wscript, mshta, cmd) and suspicious command line arguments often associated with malicious activity, such as encoded commands, hidden windows, or network resource access, specifically when executing under the SYSTEM account context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the abuse of common Windows LOLBins (Living Off the Land Binaries) like regsvr32, mshta, certutil, and rundll32 to proxy the execution of remote scripts, DLLs, or malicious payloads, a technique often used to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation or modification of Windows Registry Run or RunOnce keys where the associated file path points to suspicious directories (e.g., Temp, AppData, ProgramData, Users\Public) or utilizes living-off-the-land binaries (rundll32.exe, regsvr32.exe) residing outside of the protected System32 directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of PowerShell with suspicious command-line flags (EncodedCommand, NoProfile, WindowStyle Hidden, ExecutionPolicy Bypass) combined with either potential Base64-encoded payloads or network-based download cradles (e.g., Invoke-Expression, WebClient).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the use of built-in Windows utilities (vssadmin, wmic, powershell, wbadmin, and bcdedit) to delete volume shadow copies, backup catalogs, or modify boot configuration to prevent system recovery. This activity is commonly associated with ransomware operations to inhibit data restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000