Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects HTTP requests to the OnyxC2 backend API sync endpoint (akmuniverstall.top) carrying the characteristic hwid, ownertoken, and botversion=3.0 parameters used for device-fingerprint C2 check-ins.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects a low-level keyboard hook or screen-capture API call from an unsigned, non-standard-path process, correlated with periodic image/keystroke buffer file staging, consistent with OnyxC2's premium keylogger/screenshot module.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
204
Correlates the ShieldBreak PoC's 'Exploit succeeded' console output with a SYSTEM-privileged cmd.exe spawn in the same process session within a short window, confirming successful end-to-end exploitation of CVE-2026-50656.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects JWR phishing framework client engine script via known SHA256 hashes (standalone high-confidence), or the co-occurrence of anti-debug check, staging path structure, and Simplified Chinese operator status strings
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Correlates DNS/network requests to newly observed domains matching JWR's brand-plus-suffix generation pattern across .top/.cfd/.info/.cc TLDs, requiring multiple distinct hostnames sharing the same brand token within a short window to flag likely batch-registered phishing infrastructure.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects the hard-coded RC4 key fragment used by BTR.sys to decrypt its transaction structure when co-located within 0x4000 bytes of the FEE1DEAD magic value and Version 2 header field, targeting the encrypted transaction/ADS payload content independent of driver binary version.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
100
Detects suspicious Active Directory Replication Service (ADRS) requests originating from
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.

Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 months ago
20061
Detects additions to privileged groups (e.g. Domain Admins) or modification of password-change-policy flags on a previously dormant account being reactivated, excluding changes linked to an approved change-management ticket and weighting more heavily for off-hours or non-standard admin workstation origin.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6010
Detects creation of a scheduled task named 'IntelSoftwareUpdater' via schtasks.exe that launches pythonw.exe with run.pyw, used by the UNC5142 DeviceManager RAT for persistence, relaunching every 10 minutes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects TLS sessions to Sapphire Sleet/UNC1069 Hostwinds C2 infrastructure presenting the exact self-signed certificate issuer string linked to the Mastra/axios campaigns.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000
This rule detects network communication attempts (connection success, request, or failure, or any traffic on port 443) targeting a specific malicious domain (notepadreleased.com) or IP address (85.158.110.78), while explicitly excluding common public DNS providers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
407
Detects a non-system process causing creation of CldFlt0.etl under C:\Windows\System32\LogFiles\CloudFiles\.
This path is initialised by the CldFlt driver when a process calls CfRegisterSyncRoot() or CfConnectSyncRoot().
In the RedSun exploit this is a side-effect of the DoCloudStuff() function that registers a fake sync provider to create the cloud-tagged bait file.
Legitimate cloud providers (OneDrive etc.) register sync roots from SYSTEM-level service processes, not from user-context executables.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
001
This rule detects potentially malicious attempts to modify Windows process protection levels, often used by attackers employing Bring Your Own Vulnerable Driver (BYOVD) techniques. It identifies when processes use command-line arguments like 'PsProtectedSignerAntimalware' or 'SetProcessMitigationPolicy' to assign elevated protection levels, while simultaneously ensuring the initiating process is either unsigned or not a standard executable file, which is highly indicative of suspicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
305
This rule detects command-line activity that references sensitive Windows API functions or privileges associated with token manipulation and process privilege escalation, such as SeDebugPrivilege, SeImpersonatePrivilege, DuplicateTokenEx, CreateProcessWithTokenW, and NtSetInformationToken. The rule excludes common service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to focus on potentially unauthorized use by standard or administrative accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
105
This rule monitors for two critical firmware-related conditions: detected non-compliance with secure boot, UEFI, or TPM configuration standards via Microsoft Defender TVM, and explicit firmware or boot configuration change events reported by device telemetry. It is designed to identify potential tampering or misconfigurations that could facilitate bootkits or other pre-OS persistence mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
105
This rule identifies network connections using deprecated, insecure TLS versions (TLS 1.0, 1.1) or weak cipher suites (RC4, 3DES, NULL). The use of these legacy cryptographic protocols is a security risk, as they are vulnerable to various attacks like man-in-the-middle, and may indicate misconfigured servers, legacy infrastructure, or attempts by an adversary to downgrade encryption to facilitate traffic interception or inspection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
205
Detects the installation of a Manifest V3 browser extension that requests the 'chrome.proxy' permission as its sole permission. This behavior is indicative of potential malicious extensions designed to modify web traffic or route browser activity through an adversary-controlled proxy server.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
305
This rule detects attempts to disable, stop, or uninstall various security products, including antivirus and EDR solutions, by monitoring command-line activity for administrative utilities like sc.exe, net.exe, wmic.exe, and PowerShell.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
7011
This rule detects scenarios where a new user account is created (Event ID 4720) and is subsequently logged into (Event ID 4624) within a 30-minute window. This behavior can indicate an adversary creating a backdoor or service account for persistence or lateral movement, followed by immediate usage of that account.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
9011
Detects execution of the SimpleChatProxy/'Chat Proxy' tool correlated with outbound traffic to an attacker-hosted image endpoint, used for operator-victim messaging and remote screenshot retrieval.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects an unsigned Loader.exe spawning a second unsigned executable that performs immediate outbound network fetch, matching the StopAndProtect loader/downloader chain with sandbox-evasion checks.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Page 476 of 1870