Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects potential browser-based infostealer activity where a non-standard process, launched from temporary or user-download directories, accesses sensitive browser data files (cookies, login data) followed by a suspicious outbound network connection to a previously unseen domain, matching common patterns for LummaStealer or Vidar malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects high-risk domain account activity, specifically identifying either impossible-travel authentication patterns in cloud logs or rapid, multi-host interactive authentication fan-out within one hour. These detections are further correlated with subsequent RDP or WinRM session establishment, indicating potential lateral movement or compromise of legitimate accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
201
This rule detects potential process injection or process hollowing attempts by correlating Sysmon Event ID 10 (ProcessAccess) events indicating process memory modification permissions (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) with subsequent Sysmon Event ID 8 (CreateRemoteThread) events targeting the same process. This behavior is indicative of an adversary injecting malicious code into a legitimate host process (e.g., svchost.exe, explorer.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects processes querying registry keys or accessing file paths associated with common virtualization and sandbox environments (e.g., VMware, VirtualBox, Hyper-V, Sandboxie). This behavior is often indicative of malware attempting to identify if it is running in an analysis or sandbox environment to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects attempts to disable, stop, or reconfigure security software (Antivirus, EDR, Endpoint Protection) on Windows endpoints by abusing legitimate administrative utilities such as sc.exe, net.exe, taskkill.exe, wmic.exe, and PowerShell to tamper with service configurations or kill security-related processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects host-side indicators of potential container escapes and unauthorized access, including mounting sensitive container runtime sockets, executing containers with privileged flags, host namespace sharing, and the use of nsenter to break out of a container context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects high-privilege OAuth consent grants to applications shortly followed by suspicious mailbox modifications, such as creating new inbox or transport rules. This behavior is indicative of a post-compromise activity where an adversary uses an illicitly granted OAuth application to maintain persistence or exfiltrate data from an Exchange Online environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects high-risk administrative activity on VMware ESXi or vCenter servers that is consistent with pre-ransomware staging, such as disabling lockdown mode, disabling syslog forwarding, mass deletion or modification of virtual machine files (.vmdk/.vmx), or shell command execution related to encryption tool staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects potential exploitation of Active Directory Certificate Services (AD CS) misconfigurations (specifically ESC1, involving client-auth EKU and enrollee-supplies-subject). The rule correlates certificate issuance events (4886, 4887, 4888) involving sensitive templates or suspicious subject alternative name (SAN) mismatches with subsequent Kerberos PKINIT authentication (4768) events using the issued certificate.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule monitors network device audit logs for suspicious activities that indicate potential persistence or defense evasion on edge/VPN/router appliances. It specifically flags configuration changes, creation of new administrative accounts, addition of unauthorized SSH keys, and the disabling of logging/syslog export, which are common tactics for maintainig unauthorized access on network infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects potentially malicious activity involving Service Principals in Microsoft Entra ID. It identifies two scenarios: 1) Impossible travel, where a service principal authenticates from two distinct geographic locations within a 60-minute window, and 2) Administrative modifications to a service principal's credentials or authentication methods (e.g., adding secrets, certificates, or MFA methods), which may indicate persistence or credential abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects potential SaaS supply-chain attacks where a third-party application or connector triggers an OAuth permission scope escalation or publishes a new version, followed by the associated service account initiating outbound network connections to rare or newly-registered domains within a 24-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the reuse of a session or refresh token within a short timeframe (<= 900 seconds) where the source IP location, device identifier, or User-Agent string has materially changed. This behavior is indicative of Adversary-in-the-Middle (AiTM) attacks, where a session cookie has been stolen and replayed from an attacker's infrastructure to hijack a legitimate user's session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects a potential mass-encryption event by identifying a single host rapidly renaming or rewriting a large volume of files across multiple SMB network shares within a short timeframe, where the renamed files consistently adopt a single file extension.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects lateral movement via SMB by identifying multiple connections to Windows admin shares (ADMIN$ or C$) followed within a 10-minute window by the creation of a remote service, often indicative of techniques like PsExec. This pattern detects suspicious fan-out behavior where a single source host interacts with multiple targets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the creation of scheduled tasks via schtasks.exe or native Windows event logs that exhibit suspicious characteristics commonly associated with persistence mechanisms. These characteristics include tasks triggered at logon or system startup, tasks running with elevated SYSTEM privileges, tasks configured to be hidden, or tasks executing binaries from temporary, user-writable directories (Temp, AppData, Public). This pattern is often observed in attack chains leveraging RMM tools or delivery mechanisms like ClickFix.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Detects successful VPN authentication events where no multi-factor authentication (MFA) method is reported in the logs. This behavior may indicate an account compromise where an adversary has bypassed MFA or is using a legacy account that lacks MFA enforcement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004
Detects common Windows system binaries (svchost.exe, csrss.exe, lsass.exe, explorer.exe) executing from non-standard directories, which is a common indicator of process masquerading to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule detects unauthorized or unauthenticated attempts to call the NetrServerPasswordSet2 method on a Domain Controller via the MS-NRPC (Netlogon) interface, which is indicative of an exploitation attempt related to CVE-2020-1472 (Zerologon). This vulnerability allows an attacker to bypass authentication and reset a Domain Controller's computer account password, leading to full domain compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004
Detects the execution of LNK files masquerading as PDF files through the use of double extensions (e.g., .pdf.lnk). The rule monitors for processes spawned by explorer.exe that contain '.pdf.lnk' in the command line and trigger child processes like PowerShell, CMD, WScript, or MSHTA, which are common indicators of malicious intent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004
Detects an exploitation attempt targeting SharePoint through the EditingPageParser by injecting a Register directive. This attempt involves bypassing SafeControls through specifically crafted HTTP POST requests to ToolPane.aspx, utilizing the GetPartPreviewAndPropertiesFromMarkup function to execute malicious tag patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004