Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the use of legitimate Windows binaries (certutil.exe and bitsadmin.exe) to download files from remote URLs or perform encoding/decoding operations in suspicious directories (Temp, AppData). This activity is commonly used by adversaries for stage-one malware delivery or tool ingress.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects instances of rundll32.exe or regsvr32.exe executing from suspicious locations or with suspicious command-line arguments (e.g., URLs, JavaScript, or script file extensions) initiated by an unsigned process. This is a common technique used to proxy malicious code execution while evading security monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of PowerShell processes using suspicious command-line flags, encoding, or built-in .NET network download methods (e.g., IEX, Net.WebClient, DownloadString). The rule excludes signed PowerShell binaries and common system management tools like SCCM or monitoring agents to reduce false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects unauthorized or suspicious cross-process access attempts by monitoring relationships between source and target processes. It specifically flags instances where common target processes (e.g., browsers or core system processes) are accessed by a source process that is not on a known allowlist of legitimate parent/child or service-related processes. This pattern is often indicative of process injection or unauthorized memory access attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects potential quishing (QR code phishing) attempts by identifying emails with one or more image attachments and minimal URL content, followed by a risky user authentication event within a 3-hour window. This behavior is indicative of an attacker attempting to harvest credentials via a malicious QR code that redirects the user to a phishing site.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
203
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
004
Detects the addition or modification of federated identity credentials within Microsoft Entra ID (Azure AD). Adversaries may add these credentials to service principals or applications to achieve persistent access and potentially bypass traditional password-based authentication mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
103
Detects the creation of Windows Management Instrumentation (WMI) Event Filter, Event Consumer, or FilterToConsumerBinding objects. Attackers use these objects to create event subscriptions that trigger malicious code or scripts upon specific system events, providing a stealthy and persistent execution mechanism.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects remote thread creation (CreateRemoteThread or QueueUserAPC) into common Windows system processes (rundll32.exe or svchost.exe) originating from suspicious source processes. This activity is indicative of process injection techniques commonly utilized by Cobalt Strike beacons during post-exploitation, lateral movement, or ransomware deployment phases.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects MFA fatigue attacks (MFA prompt-bombing) characterized by repeated denied MFA attempts for a single user, or successful MFA logins that occur under high-risk sign-in conditions, which are characteristic of activity associated with Lapsus$ (DEV-0537/Strawberry Tempest).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
103
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
004
Detects the Microsoft HTML Help executable (hh.exe) spawning suspicious child processes such as command interpreters (cmd.exe, powershell.exe) or scripting engines (mshta.exe, wscript.exe). This behavior is characteristic of initial access techniques used by the Kimsuky (APT43) threat group, where malicious CHM files are delivered via email attachments to execute payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects the creation of Azure AD applications with generic display names, often combined with the addition of delegated permissions for 'Mail.Read' or 'Mail.ReadWrite' scopes. This activity is consistent with OAuth-based consent phishing campaigns used by threat groups such as APT35 (also known as Mint Sandstorm or Charming Kitten) to gain persistent access to user email environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects command-line activity indicative of DNS tunneling, often used by OilRig (APT34) for C2 communication via BONDUPDATER. The rule monitors PowerShell or nslookup commands executing DNS TXT record queries paired with long, base64-encoded subdomains, a technique used for exfiltrating data or receiving commands.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects DLL side-loading where a known legitimate signed executable, often associated with security utilities, loads a DLL from a non-standard, user-writable directory (such as Temp, AppData, or ProgramData). This behavior is characteristic of APT10's (Stone Panda/Cicada) historical tradecraft in MSP environments to execute modular PlugX RAT payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects lateral movement via PsExec (PSEXESVC) followed by mass file encryption/rename activities and the creation of ransom note files, characteristic of Wizard Spider's deployment of Conti ransomware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects network indicators associated with the Exvicy/ErrTraffic 'ClickFix' campaign. The rule identifies the retrieval of malicious HTML lure templates from compromised WordPress sites and subsequent telemetry/registration calls to an attacker-controlled 'api.php' script, which are precursors to the fake Cloudflare Turnstile 'Win+R' execution sequence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
105
Detects the execution of script interpreters (powershell, cmd, mshta, etc.) spawned directly by explorer.exe via the Run dialog, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands to bypass security mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
305
Detects instances where a user account registers a new Multi-Factor Authentication (MFA) method (such as TOTP or Authenticator app) shortly (within 30 minutes) after a high-risk or potentially anomalous sign-in event. This pattern is commonly associated with adversary-in-the-middle (AiTM) phishing attacks where an attacker captures an authenticated session and uses it to enroll a secondary, attacker-controlled MFA device for persistent account access.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
104
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000