Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects potential malicious activity by monitoring for known indicators of compromise, including specific SHA256 file hashes, a known malicious IP address, and URLs associated with identified threats. The detection spans file creation/execution, network connections, and URL visits to block or alert on interactions with suspicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
001
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
001
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
001
Detects the creation of a Windows service named 'ProcAuditManager', which is associated with the SparroWocky threat. The rule flags the service creation event (Event ID 7045) and identifies if the service description matches the known malicious signature, which attempts to masquerade as a legitimate auditing tool.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
005
Detects incoming HTTP requests to Microsoft Exchange servers that match patterns indicative of exploitation attempts for the ProxyLogon SSRF vulnerability (CVE-2021-26855). This includes detecting specific manipulation of the Autodiscover service and the injection of X-BEResource or X-AnonResource-Backend headers, which were commonly used during the initial access phase of this campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
005
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
001
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
101
Detects the execution of wmic.exe, powershell.exe, or pwsh.exe with command-line arguments related to querying antivirus products or security centers (e.g., AntiVirusProduct, SecurityCenter2). The rule focuses on executions originating from non-standard system paths (e.g., Temp, Users, AppData) or processes that lack a valid code signing signature, which is often indicative of reconnaissance by malicious actors.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
24 days ago
308
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
201
Detects potential ClickFix-style social engineering attacks where a victim is prompted to execute an encoded PowerShell command (often via copy-paste into a terminal). The rule specifically monitors PowerShell processes initiated by shell environments (explorer.exe, cmd.exe, or WindowsTerminal.exe) that execute encoded, hidden scripts to perform multiple suspicious network requests for files (e.g., .zip, .enc, .bin) from non-standard domains.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
005
Detects network and DNS activity associated with the SideCopy threat group, specifically monitoring for connections to known C2 domains, C2 IP addresses, or the usage of port 5863 typically associated with the ReverseRAT backdoor.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
001
Detects execution chains associated with the SideCopy threat group's ReverseRAT payload. The detection looks for mshta.exe being spawned by common shell processes (explorer, wscript, cmd, powershell) to execute remote HTA content or access 'docsportal.in'. It also monitors for subsequent reflective DLL loading via rundll32.exe or regsvr32.exe, which is indicative of the final ReverseRAT payload activation.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
101
Detects execution chains associated with the SideCopy threat group's ReverseRAT payload. The detection looks for mshta.exe being spawned by common shell processes (explorer, wscript, cmd, powershell) to execute remote HTA content or access 'docsportal.in'. It also monitors for subsequent reflective DLL loading via rundll32.exe or regsvr32.exe, which is indicative of the final ReverseRAT payload activation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
001
Detects execution chains associated with the SideCopy threat group's ReverseRAT payload. The detection looks for mshta.exe being spawned by common shell processes (explorer, wscript, cmd, powershell) to execute remote HTA content or access 'docsportal.in'. It also monitors for subsequent reflective DLL loading via rundll32.exe or regsvr32.exe, which is indicative of the final ReverseRAT payload activation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
001
This rule monitors for user interactions with specific domains and URLs known to be associated with suspicious or malicious activity. It aggregates data from multiple sources, including email clicks (UrlClickEvents), device network activity (DeviceNetworkEvents), device browser events (DeviceEvents), and DNS queries (DnsEvents), to identify potential exposure to these indicators of compromise.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
008
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
24052
Detects the execution of an ONVIF-related tool or process with flags indicating credential retrieval. This is often associated with the reconnaissance or credential access phase targeting IoT devices such as cameras that support the Open Network Video Interface Forum (ONVIF) protocol.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects bulk file creation of XML files associated with Dahua credential exports, likely generated by a Python script, which is indicative of credential harvesting or staging for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects suspicious process creation patterns indicative of process hollowing. The rule identifies processes spawned by common script interpreters (powershell.exe, wscript.exe, cscript.exe, conhost.exe) in a suspended state, followed by memory operations involving ntdll.dll and APIs such as NtUnmapViewOfSection or ResumeThread, which are characteristic of hollowing injection techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects execution of PowerShell commands containing indicators of in-memory AMSI (Antimalware Scan Interface) patching, specifically referencing AmsiScanBuffer, AmsiScanString, or AmsiOpenSession in conjunction with amsi.dll. This behavior is associated with the initialization stage of LausivLoader prior to its payload retrieval phase.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects execution of LausivLoader by identifying suspicious process creation patterns typically associated with process hollowing. This includes a parent process (powershell.exe or conhost.exe) launching a child process in a suspended state (CREATE_SUSPENDED), followed by behavioral indicators of memory manipulation and code replacement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Page 208 of 1871