Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects DLL side-loading where a known legitimate signed executable, often associated with security utilities, loads a DLL from a non-standard, user-writable directory (such as Temp, AppData, or ProgramData). This behavior is characteristic of APT10's (Stone Panda/Cicada) historical tradecraft in MSP environments to execute modular PlugX RAT payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects lateral movement via PsExec (PSEXESVC) followed by mass file encryption/rename activities and the creation of ransom note files, characteristic of Wizard Spider's deployment of Conti ransomware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects network indicators associated with the Exvicy/ErrTraffic 'ClickFix' campaign. The rule identifies the retrieval of malicious HTML lure templates from compromised WordPress sites and subsequent telemetry/registration calls to an attacker-controlled 'api.php' script, which are precursors to the fake Cloudflare Turnstile 'Win+R' execution sequence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
105
Detects the execution of script interpreters (powershell, cmd, mshta, etc.) spawned directly by explorer.exe via the Run dialog, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands to bypass security mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
305
Detects instances where a user account registers a new Multi-Factor Authentication (MFA) method (such as TOTP or Authenticator app) shortly (within 30 minutes) after a high-risk or potentially anomalous sign-in event. This pattern is commonly associated with adversary-in-the-middle (AiTM) phishing attacks where an attacker captures an authenticated session and uses it to enroll a secondary, attacker-controlled MFA device for persistent account access.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
104
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects successful authentication events for accounts that have been dormant for at least 90 days, correlated with suspicious activity markers such as recent failed sign-in attempts, access from an unfamiliar geographic location or ASN, or a complete absence of historical sign-in activity.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
211
Detects successful authentication events for accounts that have been dormant for at least 90 days, correlated with suspicious activity markers such as recent failed sign-in attempts, access from an unfamiliar geographic location or ASN, or a complete absence of historical sign-in activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
101
Detects high-volume account enumeration activity associated with the TeamFiltration tool, characterized by the use of legacy Microsoft Teams desktop client User-Agent strings (specific versions of Teams, Electron, and Chrome) within a short time window.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
Detects high-volume account enumeration activity associated with the TeamFiltration tool, characterized by the use of legacy Microsoft Teams desktop client User-Agent strings (specific versions of Teams, Electron, and Chrome) within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
101
Detects high-volume account enumeration activity associated with the TeamFiltration tool, characterized by the use of legacy Microsoft Teams desktop client User-Agent strings (specific versions of Teams, Electron, and Chrome) within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001
Detects the 'auto-exfil' pattern associated with the TeamFiltration tool. The rule identifies a sequence of SharePoint Online file access immediately followed by a Microsoft Graph token request from the SharePoint Online Web Client Extensibility app. To reduce noise, it mandates a very short time delta between events (<= 60 seconds) combined with either the use of an IP address/ASN not previously seen for the account in the last 14 days, or a preceding failed sign-in attempt for the account.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
Detects the 'auto-exfil' pattern associated with the TeamFiltration tool. The rule identifies a sequence of SharePoint Online file access immediately followed by a Microsoft Graph token request from the SharePoint Online Web Client Extensibility app. To reduce noise, it mandates a very short time delta between events (<= 60 seconds) combined with either the use of an IP address/ASN not previously seen for the account in the last 14 days, or a preceding failed sign-in attempt for the account.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
001
Detects the 'auto-exfil' pattern associated with the TeamFiltration tool. The rule identifies a sequence of SharePoint Online file access immediately followed by a Microsoft Graph token request from the SharePoint Online Web Client Extensibility app. To reduce noise, it mandates a very short time delta between events (<= 60 seconds) combined with either the use of an IP address/ASN not previously seen for the account in the last 14 days, or a preceding failed sign-in attempt for the account.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001
Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
Detects the TeamFiltration/UNK_CondorFiltration spray signature: a large
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001