Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects suspicious cross-process access (Sysmon Event ID 10) and remote thread creation (Sysmon Event ID 8) targeting sensitive processes such as lsass.exe, svchost.exe, and explorer.exe, which are indicative of process injection or hollowing techniques used for evasion or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects bulk or repeated attempts to stop security-related services and processes (such as EDR or AV agents) or modification of Windows Defender registry keys. This behavior is indicative of a pre-encryption phase in ransomware attacks where adversaries attempt to neutralize endpoint defenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects suspicious mobile-device HTTP traffic patterns indicative of 'quishing' (QR code phishing). The rule identifies mobile HTTP GET requests (iPhone, Android, Mobile Safari, iPad) that lack a Referer header, followed by HTTP POST requests to common credential entry URI patterns (e.g., /login, /signin) over the same protocol, which is a behavioral indicator of a user being redirected from a scanned QR code to a malicious phishing landing page.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the use of legitimate data-transfer utilities (rclone, MEGA client, restic, WinSCP) configured to exfiltrate data to cloud storage providers. This behavior is identified as a precursor to double-extortion ransomware attacks, where attackers steal sensitive data before encrypting it.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects the execution of PowerShell or MSHTA from explorer.exe with command line arguments indicative of malicious activity, such as hidden windows, Base64 encoding, or command execution (IEX/Invoke-Expression). This behavior is common in fileless malware delivery and script-based initial access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule detects the execution of the Cloudflare 'cloudflared' utility from non-standard directory locations. Cloudflared is often abused by threat actors to establish reverse tunnels (e.g., TryCloudflare) to gain unauthorized, persistent, and encrypted external access to a compromised host, effectively bypassing standard perimeter network security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects instances where common system processes (svchost.exe, explorer.exe, dllhost.exe) perform process injection activities, followed within a 5-minute window by a network connection to known SaaS and collaborative platforms (Slack, Discord, Dropbox, Trello). This combination is often indicative of malicious code executing within a trusted process to facilitate command and control or data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects the execution of common remote access and RMM (Remote Monitoring and Management) tools spawned directly from web browser processes (e.g., Chrome, Edge, Firefox). It further monitors for subsequent suspicious child process activity such as command shell execution or file operations performed by these RMM tools, which is a common pattern in post-exploitation and initial access activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule detects potentially malicious PowerShell, CMD, or PWSH command execution characterized by obfuscation techniques (such as Base64 encoding, decompression, or hidden command arguments) that are followed closely in time by network connections to public AI service domains (OpenAI, Anthropic, Google Generative Language, Mistral, Cohere). The detection correlates process-start events with outbound network requests from processes other than standard web browsers, suggesting potentially unauthorized use of AI APIs for exfiltration or automated processing of command results.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects the suspicious loading of known vulnerable drivers (Bring Your Own Vulnerable Driver - BYOVD) via the Windows service control manager (sc.exe) or event log 7045, followed by the immediate termination of major endpoint security software processes within a 300-second window. This behavior is indicative of an attempt to disable or tamper with security tools using kernel-level privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects suspicious administrative activity involving privileged users performing bulk account/object deletions or stopping critical identity-related services (ADFS, Active Directory Certificate Services). The rule specifically flags events occurring outside standard business hours, involving privileged AD groups, or directly targeting identity infrastructure, indicating a potential attempt to disrupt authentication services or sabotage identity management.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects anomalous mass file modification or renaming activity often associated with ransomware, combined with the deletion of Windows Volume Shadow Copies using native utilities like vssadmin or wmic, and the presence of suspicious ransom note filenames.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
6 days ago
000
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects instances where a user account consents to an OAuth application requesting high-privilege or sensitive scopes such as Mail.Read, Files.ReadWrite.All, or offline_access. This behavior is a common indicator of consent phishing attacks, where adversaries trick users into granting persistent access to their cloud resources via malicious OAuth applications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
201
Detects instances where a user successfully authenticates via the OAuth Device Code flow using an unmanaged or non-compliant device, followed closely by high-privileged Azure/Graph API administrative actions within a short timeframe. This behavior is indicative of a device-code phishing attack aimed at bypassing MFA controls, including FIDO2/passkeys, by compromising an active session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule detects a multi-stage Business Email Compromise (BEC) attack involving executive impersonation via look-alike domains, followed by the creation of suspicious inbox rules (forwarding/deletion) by the victim, and concurrent external communication (Teams/Zoom meeting invites) from a newly created account. It correlates these activities to identify sophisticated payment fraud campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
201