Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation of a remote thread (Sysmon Event ID 8) by a process into a set of common host processes (e.g., svchost.exe, explorer.exe) where the starting address of the thread does not map to a known loaded module. This behavior is highly indicative of reflective code injection or shellcode execution within the address space of a remote process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects suspicious PowerShell ScriptBlock logs (Event ID 4104) that attempt to bypass security features like AMSI or ETW while employing common obfuscation techniques such as Base64 encoding, reflection, or character concatenation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects periodic network connection patterns indicative of Cobalt Strike beaconing. The rule identifies low-variance jittered traffic, where the communication interval remains relatively consistent over a defined period, consistent with default Cobalt Strike malleable C2 profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the installation or execution of common Remote Monitoring and Management (RMM) tools (e.g., ScreenConnect, AnyDesk, Atera) that are initiated from potentially untrusted parent processes like browsers, mail clients, or archive utilities, or that exhibit a code signing discrepancy. The rule further correlates these installation events with subsequent modifications to the Windows firewall within a two-hour window, which is indicative of an adversary establishing remote access persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the use of BITSAdmin to download files to suspicious directories (Temp, AppData, ProgramData) or to register persistent command execution via the /SetNotifyCmdLine parameter. This detection correlates process execution events with BITS Client operational log events to confirm the completion or status of the BITS job.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects the unauthorized creation of script or executable files in the Windows Startup directory by .NET or Python runtime processes, specifically targeting the exploitation pattern of CVE-2026-25592. This vulnerability allows an AI agent host to bypass sandbox isolation and write files to the host filesystem, potentially establishing persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
104
Detects a suspected device-code phishing attack where a user visits a known malicious lure domain and shortly thereafter completes a successful Microsoft 365 device-code authentication. This rule correlates network events with sign-in logs within a 10-minute window to identify session hijacking attempts that bypass traditional MFA.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000