Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
002
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
001
This rule monitors for outbound network connections to a list of known malicious IP addresses identified as part of the GhostCode command-and-control (C2) infrastructure. It uses DeviceNetworkEvents data to flag activity originating from endpoints and highlights a specific IP address used during the Intune/MDM enrollment process for further investigation.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
308
This rule detects internal network activity (DNS queries, network connections, and security logs) communicating with domains associated with the GhostCode phishing kit. These domains are typically used to host credential harvesting pages or phishing infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
23 days ago
208
Detects Python processes (python.exe, python3.exe, pythonw.exe) performing DNS resolution for Microsoft identity, device login, or Graph API endpoints. This activity is consistent with automated tooling, such as python-requests, performing device-code flow polling or API token authentication within an environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
206
This rule detects the creation or modification of Windows Registry Run keys, which are a common technique used for achieving persistence. The rule specifically monitors for known suspicious or potentially malicious file names (e.g., RuntimeSSH.exe, MicDriver.exe, winappx.exe, MsCache.exe, smqdservice.exe) being added to Run locations, which triggers automatic execution upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
Detects modifications to HKEY_CURRENT_USER Run keys associated with the HEAVYGRAM backdoor, which uses specific filenames and patterns to establish persistence via autorun registry entries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
This rule detects potentially malicious in-memory activity within the 'GRrte.exe' process, specifically targeting behaviors associated with PlugX malware. It monitors for suspicious memory protection changes (e.g., requests for Read-Write-Execute permissions) and the loading of the 'ws2_32.dll' library, which is commonly used to facilitate network communication in side-loaded payloads.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
004
Detects high-volume file/directory enumeration behavior by the PlugX side-loaded process GRrte.exe, consistent with PlugX's use of FindFirstFileW/FindNextFileW/FindFirstFileExW for file and directory discovery (T1083).
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
204
This rule detects persistence mechanisms involving the 'JartePortable' application by monitoring Registry Run keys. It flags when a Registry key is created or modified to include a startup entry for 'Jarte.exe' located in 'C:\Users\Public\JartePortable\'. The detection specifically looks for a suspicious registry value data pattern.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
304
Detects browser extension manifest.json files requesting declarativeNetRequest and content_scripts/host_permissions covering AI assistant vendor domains (BragJack attack class)
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
107
This rule detects the opening of a specific PDF file named 'OIC_Invitation_General_Official.pdf' by Adobe Acrobat. The detection logic triggers either when Acrobat processes this file or when the file itself is identified on the system. This pattern has been associated with the delivery of the PlugX remote access tool, often used in targeted spearphishing campaigns.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
104
Detects the execution of taskkill.exe to forcibly terminate the iediagcmd.exe diagnostic process, initiated by the process GRrte.exe. This behavior is indicative of an attempt to impair security or diagnostic tools on the endpoint.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
104
This rule detects the execution of a malicious PowerShell command chain initiated by explorer.exe, consistent with the PlugX malware infection sequence. The detection monitors for specific command-line arguments, including the use of curl for file downloads, tar for extraction, and the launching of associated malicious executables like 'GRrte.exe' following the execution of a shortcut file named 'OIC_Invitation_General_Official.lnk'.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
204
Detects Microsoft Exchange Control Panel (ECP) worker process (w3wp.exe) spawning suspicious child processes (e.g., cmd.exe, powershell.exe, mshta.exe) that are commonly associated with the exploitation of CVE-2020-0688. This vulnerability involves unsafe deserialization within the Exchange ECP ViewState handling, which allows an attacker to execute arbitrary code with SYSTEM privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
006
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
17 days ago
001
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
17 days ago
001
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
001
This rule monitors for outbound network connections to domains and IP addresses associated with known phishing, loader, and C2 infrastructure, including specific ClickFix patterns.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
29 days ago
16044
Detects the execution of suspicious binaries from the user's AppData Local Temp directory, often associated with AutoIt scripting or similar automation tools that utilize configuration (.ini) files to drive malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of suspicious binaries from the user's AppData Local Temp directory, often associated with AutoIt scripting or similar automation tools that utilize configuration (.ini) files to drive malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Page 188 of 1871