Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the execution of files ending in '_win64.exe' from 'Perflogs' or 'Documents' directories, which is a known behavior of the Settra ransomware. The rule filters out common system and program file paths to reduce noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
103
Detects potential ransomware activity characterized by the mass renaming of files with specific extensions (.locked, .locked_wip) or the creation of known ransomware note filenames (RESTORE_FILES.txt) on a Windows system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
103
Detects the BotHelper RAT performing live screen surveillance by identifying repeated high-frequency JPEG frame uploads to the '/api/v1/screen_live.php' endpoint, initiated by the 'msedge_proxy.exe' process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
503
The following analytic detects the execution of tools commonly exploited by cybercriminals, such as those used for unauthorized access, network scanning, privilege escalation, password dumping or data exfiltration.
It leverages process activity data from Endpoint Detection and Response (EDR) agents, focusing on known attacker tool names.
This activity is significant because it serves as an early warning system for potential security incidents, enabling prompt response. If confirmed malicious, this activity could lead to unauthorized access, data theft, or further network compromise, posing a severe threat to the organization's security infrastructure.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This analytic detects suspicious python package installations where the package name resembles popular Python libraries but may be typosquatted or slightly altered.
Typosquatting is a common technique used by attackers to trick users into installing malicious packages that mimic legitimate ones.
This detection leverages Cisco NVM flow telemetry and checks for pip or poetry package managers with the "install" or "add" flags, making outbound connections to package repository such as `pypi.org` with known or suspected typo package names.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects any outbound network connection from an endpoint process to a known suspicious or non-standard port.
It leverages Cisco Network Visibility Module flow data logs to identify potentially suspicious behavior by looking at processes
communicating over ports like 4444, 2222, or 51820 are commonly used by tools like Metasploit, SliverC2 or other pentest, red team or malware.
These connections are worth investigating further, especially when initiated by unexpected or non-network-native binaries.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects modifications to files with extensions commonly associated with ransomware. It leverages the Endpoint.Filesystem data model to identify changes in file extensions that match known ransomware patterns.
This activity is significant because it suggests an attacker is attempting to encrypt or alter files, potentially leading to severe data loss and operational disruption.
If confirmed malicious, this activity could result in the encryption of critical data, rendering it inaccessible and causing significant damage to the organization's data integrity and availability.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the writing of files from known remote access software to disk within the environment.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on file path, file name, and user information.
This activity is significant as adversaries often use remote access tools like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access.
If confirmed malicious, this could allow attackers to persist in the environment, potentially leading to data exfiltration, further compromise, or complete control over affected systems.
It is best to update both the remote_access_software_usage_exception.csv lookup and the remote_access_software lookup with any known or approved remote access software to reduce false positives and increase coverage.
In order to enhance performance, the detection filters for specific file names extensions / names that are used in the remote_access_software lookup.
If add additional entries, consider updating the search filters to include those file names / extensions as well, if not alread covered.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the execution of processes with file or code signing attributes from known remote access software within the environment. It leverages Sysmon EventCode 1 data and cross-references a lookup table of remote access utilities such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer. This activity is significant as adversaries often use these tools to maintain unauthorized remote access. If confirmed malicious, this could allow attackers to persist in the environment, potentially leading to data exfiltration or further compromise of the network.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects when a known remote access software is added to common persistence locations on a device within the environment. Adversaries use these utilities to retain remote access capabilities to the environment. Utilities in the lookup include AnyDesk, GoToMyPC, LogMeIn, TeamViewer and much more. Review the lookup for the entire list and add any others.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies the first-time execution of child processes spawned by Zoom (zoom.exe or zoom.us). It leverages Endpoint Detection and Response (EDR) data, specifically monitoring process creation events and comparing them against previously seen child processes. This activity is significant because the execution of unfamiliar child processes by Zoom could indicate malicious exploitation or misuse of the application. If confirmed malicious, this could lead to unauthorized code execution, data exfiltration, or further compromise of the endpoint.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies system processes running from unexpected locations outside of paths such as `C:\Windows\System32\` or `C:\Windows\SysWOW64`. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process paths, names, and hashes. This activity is significant as it may indicate a malicious process attempting to masquerade as a legitimate system process. If confirmed malicious, this behavior could allow an attacker to execute code, escalate privileges, or maintain persistence within the environment, posing a significant security risk.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects modifications to the Access Control List (ACL) of the AdminSDHolder object in a Windows domain, specifically the addition of new rules. It leverages EventCode 5136 from the Security Event Log, focusing on changes to the nTSecurityDescriptor attribute. This activity is significant because the AdminSDHolder object secures privileged group members, and unauthorized changes can allow attackers to establish persistence and escalate privileges. If confirmed malicious, this could enable an attacker to control domain-level permissions, compromising the entire Active Directory environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This detection identifies an Active Directory access-control list (ACL) modification event, which applies permissions that deny the ability to enumerate permissions of the object.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This detection monitors the addition of the following ACLs to an Active Directory group object: "Full control", "All extended rights", "All validated writes", "Create all child objects", "Delete all child objects", "Delete subtree", "Delete", "Modify permissions", "Modify owner", and "Write all properties". Such modifications can indicate potential privilege escalation or malicious activity. Immediate investigation is recommended upon alert.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This detection monitors the addition of the following ACLs to an Active Directory user object: "Full control","All extended rights","All validated writes", "Create all child objects","Delete all child objects","Delete subtree","Delete","Modify permissions","Modify owner","Write all properties". Such modifications can indicate potential privilege escalation or malicious activity. Immediate investigation is recommended upon alert.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This detection identifies an Active Directory access-control list (ACL) modification event, which applies the minimum required extended rights to perform the DCShadow attack.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the disabling of audit policies on a domain controller. It leverages EventCode 4719 from Windows Security Event Logs to identify changes where success or failure auditing is removed. This activity is significant as it suggests an attacker may have gained access to the domain controller and is attempting to evade detection by tampering with audit policies. If confirmed malicious, this could lead to severe consequences, including data theft, privilege escalation, and full network compromise. Immediate investigation is required to determine the source and intent of the change.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the addition of permissions required for a DCSync attack, specifically DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set. It leverages EventCode 5136 from the Windows Security Event Log to identify when these permissions are granted. This activity is significant because it indicates potential preparation for a DCSync attack, which can be used to replicate AD objects and exfiltrate sensitive data. If confirmed malicious, an attacker could gain extensive access to Active Directory, leading to severe data breaches and privilege escalation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
ACL deletion performed on the domain root object, significant AD change with high impact. Following MS guidance all changes at this level should be reviewed. Drill into the logonID within EventCode 4624 for information on the source device during triage.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
ACL modification performed on the domain root object, significant AD change with high impact. Following MS guidance all changes at this level should be reviewed. Drill into the logonID within EventCode 4624 for information on the source device during triage.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
Page 20 of 1866