Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects potential HTML smuggling activity by identifying a browser process writing an executable file named 'config.exe' to the user's Downloads folder without a traditional network download event, followed immediately by Microsoft Defender SmartScreen or Antivirus reporting a warning or scan failure on the file. This behavior is indicative of a payload being reconstructed on the client-side via JavaScript blobs or data URLs, which is a common characteristic of HTML smuggling delivery chains.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects HTTP GET requests to Cloudflare Pages subdomains (.pages.dev) ending in '/File_download', often used as a distribution point for malicious HTA (HTML Application) or WSF (Windows Script File) payloads in spearphishing campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects UAT-11587 Stage 1 HTA and WSF stager template: hidden/zero-sized window, fixed Cloudflare Pages tracking beacon with ?track, and WinHttp/MSXML ActiveXObject loading Stage 2 from Cloudflare R2 or CloudFront.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects an authentication pattern characteristic of credential compromise, consisting of a burst of failed authentication attempts against an account within a short window, followed immediately by a successful sign-in from an anomalous or new device/location. This pattern is indicative of brute-force or credential spraying followed by successful validation and potential lateral movement.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects an authentication pattern characteristic of credential compromise, consisting of a burst of failed authentication attempts against an account within a short window, followed immediately by a successful sign-in from an anomalous or new device/location. This pattern is indicative of brute-force or credential spraying followed by successful validation and potential lateral movement.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects an authentication pattern characteristic of credential compromise, consisting of a burst of failed authentication attempts against an account within a short window, followed immediately by a successful sign-in from an anomalous or new device/location. This pattern is indicative of brute-force or credential spraying followed by successful validation and potential lateral movement.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects a multi-stage attack chain originating with a healthcare-themed phishing email (e.g., billing or patient coordination lures) that leads to a link click, followed by a subsequent suspicious user sign-in from a non-managed/non-compliant device for the same recipient. This correlates email threat data, URL click telemetry, and sign-in logs to identify potential credential harvesting.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a multi-stage attack chain originating with a healthcare-themed phishing email (e.g., billing or patient coordination lures) that leads to a link click, followed by a subsequent suspicious user sign-in from a non-managed/non-compliant device for the same recipient. This correlates email threat data, URL click telemetry, and sign-in logs to identify potential credential harvesting.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects a multi-stage attack chain originating with a healthcare-themed phishing email (e.g., billing or patient coordination lures) that leads to a link click, followed by a subsequent suspicious user sign-in from a non-managed/non-compliant device for the same recipient. This correlates email threat data, URL click telemetry, and sign-in logs to identify potential credential harvesting.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a multi-stage attack chain originating with a healthcare-themed phishing email (e.g., billing or patient coordination lures) that leads to a link click, followed by a subsequent suspicious user sign-in from a non-managed/non-compliant device for the same recipient. This correlates email threat data, URL click telemetry, and sign-in logs to identify potential credential harvesting.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects Heartbleed (CVE-2014-0160) exploitation attempts by monitoring for malformed TLS heartbeat requests (undersized payload) followed by oversized responses from the server that indicate potential memory disclosure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects potential lateral movement or compromised account use where a single user identity authenticates to multiple distinct cloud or administrative resources within a short time window (15 minutes). The rule uses a threshold of six or more unique applications or resources to identify anomalous patterns typical of reconnaissance or mass resource access often associated with stolen credentials. Administrative, service, and automation-related accounts are excluded to minimize noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000