Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
This rule detects attempts to disable or tamper with Microsoft Defender security features by monitoring for unauthorized modifications to specific registry keys (DisableAntiSpyware, DisableRealtimeMonitoring, or the WinDefend service start type) in conjunction with related process execution activity (e.g., PowerShell, cmd, reg, or MpCmdRun) that includes keywords associated with defender configuration changes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
This rule identifies DNS queries or web requests directed toward a known list of domain names associated with the 'ShipmentsFree' family of shipping-rebate scams. These scams are typically designed to lure consumers into unknowingly signing up for recurring, undisclosed subscription services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
Detects instances where the ScreenConnect ClientService process initiates a child process that is not a recognized ScreenConnect binary. It further filters for child processes created shortly after a file has been created or modified by the ScreenConnect service, which is often indicative of an adversary using the remote access tool to drop and execute malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
105
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
Page 200 of 1871