Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects the execution of common remote access and RMM (Remote Monitoring and Management) tools spawned directly from web browser processes (e.g., Chrome, Edge, Firefox). It further monitors for subsequent suspicious child process activity such as command shell execution or file operations performed by these RMM tools, which is a common pattern in post-exploitation and initial access activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule detects potentially malicious PowerShell, CMD, or PWSH command execution characterized by obfuscation techniques (such as Base64 encoding, decompression, or hidden command arguments) that are followed closely in time by network connections to public AI service domains (OpenAI, Anthropic, Google Generative Language, Mistral, Cohere). The detection correlates process-start events with outbound network requests from processes other than standard web browsers, suggesting potentially unauthorized use of AI APIs for exfiltration or automated processing of command results.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects the suspicious loading of known vulnerable drivers (Bring Your Own Vulnerable Driver - BYOVD) via the Windows service control manager (sc.exe) or event log 7045, followed by the immediate termination of major endpoint security software processes within a 300-second window. This behavior is indicative of an attempt to disable or tamper with security tools using kernel-level privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects suspicious administrative activity involving privileged users performing bulk account/object deletions or stopping critical identity-related services (ADFS, Active Directory Certificate Services). The rule specifically flags events occurring outside standard business hours, involving privileged AD groups, or directly targeting identity infrastructure, indicating a potential attempt to disrupt authentication services or sabotage identity management.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects anomalous mass file modification or renaming activity often associated with ransomware, combined with the deletion of Windows Volume Shadow Copies using native utilities like vssadmin or wmic, and the presence of suspicious ransom note filenames.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
6 days ago
000
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects instances where a user account consents to an OAuth application requesting high-privilege or sensitive scopes such as Mail.Read, Files.ReadWrite.All, or offline_access. This behavior is a common indicator of consent phishing attacks, where adversaries trick users into granting persistent access to their cloud resources via malicious OAuth applications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
201
Detects instances where a user successfully authenticates via the OAuth Device Code flow using an unmanaged or non-compliant device, followed closely by high-privileged Azure/Graph API administrative actions within a short timeframe. This behavior is indicative of a device-code phishing attack aimed at bypassing MFA controls, including FIDO2/passkeys, by compromising an active session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule detects a multi-stage Business Email Compromise (BEC) attack involving executive impersonation via look-alike domains, followed by the creation of suspicious inbox rules (forwarding/deletion) by the victim, and concurrent external communication (Teams/Zoom meeting invites) from a newly created account. It correlates these activities to identify sophisticated payment fraud campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
201
Detects the installation of browser extensions that utilize sensitive permissions (e.g., full URL access, cookie access) followed shortly by network connections to potentially non-reputable domains within one hour of the installation. This pattern is indicative of malicious browser extensions established for data exfiltration or credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects potential browser-based infostealer activity where a non-standard process, launched from temporary or user-download directories, accesses sensitive browser data files (cookies, login data) followed by a suspicious outbound network connection to a previously unseen domain, matching common patterns for LummaStealer or Vidar malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects high-risk domain account activity, specifically identifying either impossible-travel authentication patterns in cloud logs or rapid, multi-host interactive authentication fan-out within one hour. These detections are further correlated with subsequent RDP or WinRM session establishment, indicating potential lateral movement or compromise of legitimate accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
201
This rule detects potential process injection or process hollowing attempts by correlating Sysmon Event ID 10 (ProcessAccess) events indicating process memory modification permissions (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) with subsequent Sysmon Event ID 8 (CreateRemoteThread) events targeting the same process. This behavior is indicative of an adversary injecting malicious code into a legitimate host process (e.g., svchost.exe, explorer.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects processes querying registry keys or accessing file paths associated with common virtualization and sandbox environments (e.g., VMware, VirtualBox, Hyper-V, Sandboxie). This behavior is often indicative of malware attempting to identify if it is running in an analysis or sandbox environment to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects attempts to disable, stop, or reconfigure security software (Antivirus, EDR, Endpoint Protection) on Windows endpoints by abusing legitimate administrative utilities such as sc.exe, net.exe, taskkill.exe, wmic.exe, and PowerShell to tamper with service configurations or kill security-related processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects host-side indicators of potential container escapes and unauthorized access, including mounting sensitive container runtime sockets, executing containers with privileged flags, host namespace sharing, and the use of nsenter to break out of a container context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101