Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
002
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
002
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
002
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
002
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
001
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
002
This rule detects network connections and DNS queries directed towards specific malicious domains or domains matching a pattern hosted on pages.dev, a service frequently abused for hosting malicious infrastructure such as phishing pages or command-and-control beacons.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
19 days ago
002
This rule detects network connections and DNS queries directed towards specific malicious domains or domains matching a pattern hosted on pages.dev, a service frequently abused for hosting malicious infrastructure such as phishing pages or command-and-control beacons.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
19 days ago
002
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
19 days ago
002
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
19 days ago
002
This rule monitors DeviceNetworkEvents and DnsEvents for connections to known malicious domains and IP addresses associated with phishing campaigns. It alerts on any network communication or DNS resolution attempt targeting these indicators, providing visibility into potential user interaction with phishing infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
19 days ago
002
This rule monitors DeviceNetworkEvents and DnsEvents for connections to known malicious domains and IP addresses associated with phishing campaigns. It alerts on any network communication or DNS resolution attempt targeting these indicators, providing visibility into potential user interaction with phishing infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
19 days ago
002
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
19 days ago
002
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
19 days ago
002
This rule monitors DeviceNetworkEvents and DnsEvents for connections to known malicious domains and IP addresses associated with phishing campaigns. It alerts on any network communication or DNS resolution attempt targeting these indicators, providing visibility into potential user interaction with phishing infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
002
ChainScript file manager 'files' task: node.exe performing high-volume recursive deletion within masqueraded ChainScript installation paths (drive enumeration, dir listing, file read/write, recursive delete)
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
002
Detects when a single process terminates two or more critical security, database, or backup related processes within a short window. This behavior is often associated with adversary attempts to disable security controls or disrupt database operations, commonly observed during the impact phase of an attack or preparatory to data destruction/encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
Detects execution of PowerShell commands that utilize hidden window styles and encoded payloads, specifically when the command line or image path references 'WindowsUpdate.log'. This pattern is often used by adversaries to hide malicious scripts and potentially interact with logs in an attempt to masquerade or tamper with Windows Update processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
Detects the use of native system utilities including wmic, vssadmin, and wbadmin to delete Volume Shadow Copies or the Backup Catalog, as well as the deletion of local snapshots on macOS via tmutil. These actions are common techniques employed by ransomware to prevent system restoration after encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
This rule monitors process execution and registry modifications for filenames, process command lines, or registry keys associated with 'truesight.sys' and 'rentdrv2.sys'. These artifacts are typically associated with malicious kernel-mode drivers, such as rootkits, often used for stealth or persistence on Windows systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
105
This rule monitors DeviceNetworkEvents for any outbound network connections initiated from Windows devices to the domain 'files.surveillance-online.com', which is associated with malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
002
Page 191 of 1871