Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of rundll32.exe with command-line arguments that include references to 'WindowsUpdate.log' and a specific ordinal or function index. This pattern is commonly associated with attempts to leverage rundll32.exe to execute arbitrary code while masquerading as legitimate Windows update operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
Detects when three or more critical security, database, or service processes are terminated on a Windows host within a short timeframe. This behavior is often indicative of an adversary attempting to disable security monitoring (e.g., Windows Defender/MsMpEng.exe) or perform disruptive activity against critical infrastructure (e.g., SQL Server processes).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
Detects the creation, modification, or execution of known malicious files associated with the Kimsuky threat actor, based on a static list of MD5 hashes observed in their campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
102
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
002
This rule detects network connections and DNS queries directed towards specific malicious domains or domains matching a pattern hosted on pages.dev, a service frequently abused for hosting malicious infrastructure such as phishing pages or command-and-control beacons.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
102
This rule monitors DeviceNetworkEvents and DnsEvents for any network connection attempts or DNS queries directed towards the known malicious domain 'hyundaiservisiankara.com'. This pattern is indicative of a host attempting to communicate with an external C2 infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
102
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
002
Detects a suspected malicious sequence associated with RatHat activity. The rule identifies a device fetching an injection template configuration from a remote URL, followed by the exfiltration of credentials or form data to specific API endpoints on the same device within a 15-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
This rule detects suspicious activity where a node.exe process, often associated with a node-pty terminal emulation, launches common Windows command-line shells (cmd.exe, powershell.exe) from specific file paths or directories. This behavior is indicative of a Node.js-based Remote Access Trojan (RAT) or shell spawning mechanism being used to establish command and control or persistence on a Windows host.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
002
Detects outbound WebSocket connections from endpoints containing specific JWR phishing framework session tokens (JWRCID/JWRCVV) or known C2 path suffixes. This pattern indicates active communication with a malicious C2 server used for session hijacking or proxy-based phishing operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
This rule detects when the Node.js runtime process (node.exe) initiates the Windows command interpreter (cmd.exe) with the '/c' flag, which is commonly used to execute commands or scripts. This behavior is frequently associated with malicious Node.js activity, such as Remote Access Trojans (RATs) or web shells, which may use the shell to execute system-level operations or bypass typical application constraints.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
002
Detects processes attempting to open a handle to the Local Security Authority Subsystem Service (LSASS) process with access rights commonly associated with credential dumping. This detection focuses on identifying suspicious cross-process access requests originating from non-standard or non-authorized processes, such as those used by C2 frameworks like OnyxC2 for extracting cached Windows credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
002
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
001
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
001
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy the Active Directory database file (ntds.dit) from the shadow copy. This pattern is commonly used by adversaries to perform offline credential dumping.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
24 days ago
5010
Detects potential exploitation of CVE-2025-3248 in Langflow by identifying suspicious inbound network traffic targeting the /api/v1/validate/code endpoint, correlated with subsequent python child processes containing base64 decoding and execution primitives such as eval, exec, or subprocess.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
1010
This rule detects PowerShell processes executing with hidden window styles while performing web-based download operations from GitHub domains. It further identifies potential nested PowerShell execution, which is often used in obfuscated download-and-execute attack chains.
avatar
F S@Fsdr
avatar
Detections.ai Community
26 days ago
6014
This rule detects the addition or modification of Windows Firewall rules by applications residing in non-standard or suspicious directories. It monitors Security Events 2004, 2071, and 2097, filtering out known legitimate system paths, common temporary directories, and updates from trusted Microsoft processes such as Windows Defender, svchost.exe, and dllhost.exe. By excluding standard operating system folders and common software installation paths, the rule highlights potentially malicious attempts to establish persistence or facilitate unauthorized network communication by bypassing standard firewall management channels.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
102
Detects the execution of specific web browsers (Chrome, Edge, Opera) to facilitate identification of vulnerable browser versions as indicated by CVE-2026-0628 and CVE-2026-55945. This rule does not perform version checking directly but serves as a telemetry trigger for external asset inventory correlation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
006
Detects in-memory modification of the AmsiScanBuffer function within PowerShell processes, specifically targeting the injection of patch instructions (e.g., MOV EAX, 80070057; RET). This technique is characteristic of .NET loaders like PIVOTPIPE attempting to bypass Antimalware Scan Interface (AMSI) inspection before executing malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Page 192 of 1871