Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This detection identifies when a a new client side extension is added to an Active Directory Group Policy using the Group Policy Management Console.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This analytic is looking for when an ACL is applied to an OU which denies listing the objects residing in the OU. This activity combined with modifying the owner of the OU will hide AD objects even from domain administrators.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
AD Object Owner Updated. The owner provides Full control level privileges over the target AD Object. This event has significant impact alone and is also a precursor activity for hiding an AD object.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies when the SID of a privileged user is added to the SID History attribute of another user. It leverages Windows Security Event Codes 4742 and 4738, combined with identity lookups, to detect this activity. This behavior is significant as it may indicate an attempt to abuse SID history for unauthorized access across multiple domains. If confirmed malicious, this activity could allow an attacker to escalate privileges or maintain persistent access within the environment, posing a significant security risk.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This detection identifies when users are added to privileged Active Directory
groups by leveraging the Windows Security Event Code 4728 along with a lookup
of privileged AD groups provided by Splunk Enterprise Security.
Attackers often add user accounts to privileged AD groups to escalate privileges
or maintain persistence within an Active Directory environment.
Monitoring for modifications to privileged groups can help identify potential security breaches
and unauthorized access attempts.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
Detect when a user creates a new DACL in AD for their own AD object.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects DNS queries initiated by the Windows AI Platform to domains associated with Hugging Face, OpenAI, and other popular providers of machine learning models and services. Monitoring these DNS requests is important because it can reveal when systems are accessing external AI platforms, which may indicate the use of third-party AI resources or the transfer of sensitive data outside the organization’s environment. Detecting such activity enables organizations to enforce data governance policies, prevent unapproved use of external AI services, and maintain visibility into potential data exfiltration risks. Proactive monitoring provides better control over AI model usage and helps safeguard organizational data flows.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects attempts to bypass application restrictions by identifying Windows AppLocker policy violations. It leverages Windows AppLocker event logs, specifically EventCodes 8007, 8004, 8022, 8025, 8029, and 8040, to pinpoint blocked actions. This activity is significant for a SOC as it highlights potential unauthorized application executions, which could indicate malicious intent or policy circumvention. If confirmed malicious, this activity could allow an attacker to execute unauthorized applications, potentially leading to further system compromise or data exfiltration.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic utilizes Windows AppLocker event logs to identify attempts to bypass application restrictions. AppLocker is a feature that allows administrators to specify which applications are permitted to run on a system. This analytic is designed to identify attempts to bypass these restrictions, which could be indicative of an attacker attempting to escalate privileges. The analytic uses EventCodes 8007, 8004, 8022, 8025, 8029, and 8040 to identify these attempts. The analytic will identify the host, full file path, and target user associated with the bypass attempt. These EventCodes are related to block events and focus on 5 attempts or more.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects attempts to stop security-related services on an endpoint, which may indicate malicious activity. It leverages data from Endpoint Detection and Response (EDR) agents, specifically searching for processes involving the "sc.exe" or "net.exe" command with the "stop" parameter or the PowerShell "Stop-Service" cmdlet. This activity is significant because disabling security services can undermine the organization's security posture, potentially leading to unauthorized access, data exfiltration, or further attacks like malware installation or privilege escalation. If confirmed malicious, this behavior could compromise the endpoint and the entire network, necessitating immediate investigation and response.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This detection searches for ASR audit events that are generated when a process or application attempts to perform an action that would be blocked by an ASR rule, but is allowed to proceed for auditing purposes.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This detection searches for ASR block events that are generated when a process or application attempts to perform an action that is blocked by an ASR rule.
Typically, these will be enabled in block most after auditing and tuning the ASR rules themselves.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects modifications to Windows Defender Attack Surface Reduction (ASR) registry settings. It leverages Windows Defender Operational logs, specifically EventCode 5007, to identify changes in ASR rules. This activity is significant because ASR rules are designed to block actions commonly used by malware to exploit systems. Unauthorized modifications to these settings could indicate an attempt to weaken system defenses. If confirmed malicious, this could allow an attacker to bypass security measures, leading to potential system compromise and data breaches.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies when a Windows Defender ASR rule disabled events. ASR is a feature of Windows Defender Exploit Guard that prevents actions and apps that are typically used by exploit-seeking malware to infect machines. ASR rules are applied to processes and applications. When a process or application attempts to perform an action that is blocked by an ASR rule, an event is generated. This detection searches for ASR rule disabled events that are generated when an ASR rule is disabled.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies security events from Microsoft Defender, focusing on Exploit Guard and Attack Surface Reduction (ASR) features. It detects Event IDs 1121, 1126, 1131, and 1133 for blocked operations, and Event IDs 1122, 1125, 1132, and 1134 for audit logs. Event ID 1129 indicates user overrides, while Event ID 5007 signals configuration changes. This detection uses a lookup to correlate ASR rule GUIDs with descriptive names. Monitoring these events is crucial for identifying unauthorized operations, potential security breaches, and policy enforcement issues. If confirmed malicious, attackers could bypass security measures, execute unauthorized actions, or alter system configurations.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the execution of native .NET binaries from non-standard directories within the Windows operating system.
It leverages Endpoint Detection and Response (EDR) telemetry, comparing process names and original file names against a predefined lookup "is_net_windows_file".
This activity is significant because adversaries may move .NET binaries to unconventional paths to evade detection and execute malicious code.
If confirmed malicious, this behavior could allow attackers to execute arbitrary code, escalate privileges, or maintain persistence within the environment, posing a significant security risk.
Also this analytic leverages a sub-search to enhance performance. sub-searches have limitations on the amount of data they can return. Keep this in mind if you have an extensive list of ransomware note file names.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This Analytic detects the execution of a process attempting to access the hosts file.
The hosts file is a critical file for network configuration and DNS resolution.
If an attacker gains access to it, they can redirect traffic to malicious websites, serve fake content or block legitimate security websites.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies the use of protocol handlers executed via the command line. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry. This activity is significant because protocol handlers can be exploited to execute arbitrary commands or launch applications, potentially leading to unauthorized actions. If confirmed malicious, an attacker could use this technique to gain code execution, escalate privileges, or maintain persistence within the environment, posing a significant security risk.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the disabling of important audit policies. It leverages EventCode 4719 from Windows Security Event Logs to identify changes where success or failure auditing is removed. This activity is significant as it suggests an attacker may have gained access to the domain controller and is attempting to evade detection by tampering with audit policies. If confirmed malicious, this could lead to severe consequences, including data theft, privilege escalation, and full network compromise. Immediate investigation is required to determine the source and intent of the change.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies the creation of Dynamic Link Libraries (DLLs) with a known history of exploitation in atypical locations. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and filesystem events. This activity is significant as it may indicate DLL search order hijacking or sideloading, techniques used by attackers to execute arbitrary code, maintain persistence, or escalate privileges. If confirmed malicious, this activity could allow attackers to blend in with legitimate operations, posing a severe threat to system integrity and security.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects when DLLs with known abuse history are loaded from an unusual location.
This activity may represent an attacker performing a DLL search order or sideload hijacking technique.
These techniques are used to gain persistence as well as elevate privileges on the target system.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
Page 21 of 1866