Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects potential Cobalt Strike SMB beacon activity by identifying the creation of suspicious named pipes (commonly associated with Cobalt Strike) and correlating them with low-jitter, uniform outbound network communication patterns typical of command and control (C2) beaconing behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Active Directory enumeration consistent with BloodHound/SharpHound collection: SharpHound.exe or PowerView cmdlet process/command-line signatures, matching PowerShell script block log content, and bursts of LDAP traffic (ports 389/636) from a single source to a domain controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule identifies potential lateral movement or account compromise by detecting accounts that have performed NTLM network logons or authentication (Events 4624/4776) without corresponding Kerberos pre-authentication or interactive logon events within a 15-minute window. This pattern often indicates the use of stolen credentials (e.g., Pass-the-Hash) to access network resources rather than standard interactive user activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Windows Security (1102) or System (104) log clearing events that occur within 30 minutes of privileged activity (new account creation, group membership changes, or service installation) on the same host, sharply reducing false positives versus alerting on log clears alone.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects potential Cobalt Strike SMB beacon activity by identifying the creation of suspicious named pipes (commonly associated with Cobalt Strike) and correlating them with low-jitter, uniform outbound network communication patterns typical of command and control (C2) beaconing behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects potential DNS tunneling or DNS-based command and control (C2) beaconing. It analyzes DNS query logs for characteristics typical of C2 traffic, such as high subdomain entropy, frequent use of TXT or NULL records, and a high volume of unique subdomains originating from a single source IP address within a 5-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the Print Spooler service (spoolsv.exe) spawning a shell/script interpreter or rundll32.exe as a child process, or loading a DLL from a driver-store/temp/ProgramData path — the process-injection and arbitrary-DLL-load pattern characteristic of PrintNightmare (CVE-2021-34527) exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Active Directory enumeration consistent with BloodHound/SharpHound collection: SharpHound.exe or PowerView cmdlet process/command-line signatures, matching PowerShell script block log content, and bursts of LDAP traffic (ports 389/636) from a single source to a domain controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a suspicious sequence of events where a user exhibits signs of account compromise—either through impossible travel patterns or the use of OAuth tokens on a new device—followed within one hour by the modification of mailbox settings, such as creating new inbox rules or modifying mailbox permissions, which is a common indicator of persistence and email exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects potential Pass-the-Hash lateral movement by identifying NTLM network/remote-interactive logons from a single user account across three or more distinct destination hosts within a 15-minute window, correlated with the usage of common credential-dumping tools or commands on the source host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Directory Service Access) associated with specific Directory Replication Service (DRS) extended rights GUIDs. The rule identifies accounts attempting to perform replication tasks against a Domain Controller, filtering out events originating from recognized Domain Controllers to isolate unauthorized access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of a Volume Shadow Copy followed by an attempt to copy the NTDS.dit file from the shadow copy device path. This sequence is a common technique used by attackers to bypass file locks and extract Active Directory credential databases.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of a process from a non-standard writable directory (e.g., Temp, Downloads, AppData) which subsequently loads an unsigned DLL from the same directory within two minutes of process creation. This behavior is indicative of DLL side-loading, where an adversary uses a legitimate, potentially signed application to load a malicious DLL, bypassing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects high volumes of TGS-REQ events using RC4 encryption (etype 0x17) originating from a single account within a 10-minute window, excluding known service accounts and computer accounts. This pattern is often indicative of an adversary attempting to harvest service account tickets for offline brute-force cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the modification of Windows Run or RunOnce registry keys to execute applications from suspicious paths (e.g., Temp, AppData) or trigger PowerShell commands that contain suspicious arguments or patterns, indicating potential persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of scheduled tasks using schtasks.exe that execute common script interpreters (powershell.exe, wscript.exe, mshta.exe, cscript.exe) from user-writable or temporary directories (Temp, AppData, ProgramData, Users\Public). This activity often indicates an attempt to establish persistence or run malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects unauthorized or suspicious processes attempting to access the memory of the Local Security Authority Subsystem Service (LSASS). It specifically targets memory access (EventID 10) with sensitive access masks (e.g., PROCESS_QUERY_LIMITED_INFORMATION, PROCESS_VM_READ) originating from processes executing from suspicious locations such as Temp, AppData, Downloads, or randomly generated executable names. This method is often used by modern credential dumpers, such as those utilizing direct or indirect syscalls, to bypass userland security hooks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of known living-off-the-land binaries or network utilities initiated by or involving processes related to the Semantic Kernel framework (e.g., SKAgent, kernel.run). This pattern is often indicative of automated execution, potentially associated with agent-based activity or malicious orchestration leveraging AI framework components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
304
Detects the creation of a remote thread (Sysmon Event ID 8) by a process into a set of common host processes (e.g., svchost.exe, explorer.exe) where the starting address of the thread does not map to a known loaded module. This behavior is highly indicative of reflective code injection or shellcode execution within the address space of a remote process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects suspicious PowerShell ScriptBlock logs (Event ID 4104) that attempt to bypass security features like AMSI or ETW while employing common obfuscation techniques such as Base64 encoding, reflection, or character concatenation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects periodic network connection patterns indicative of Cobalt Strike beaconing. The rule identifies low-variance jittered traffic, where the communication interval remains relatively consistent over a defined period, consistent with default Cobalt Strike malleable C2 profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000