Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
001
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
001
Detects the creation of image files (.bmp, .png, .jpg, .jpeg) by processes executing from non-standard directories such as AppData or ProgramData. This behavior is indicative of unauthorized screen capture activities often used by malware for pattern-of-life monitoring, where screenshots are staged in temporary locations before exfiltration. The rule filters out common legitimate applications known to perform screen captures.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects instances of common interpreter processes, specifically node.exe or python variants, accessing known cryptocurrency wallet files or mnemonic storage files on a Windows system. This behavior is highly indicative of malicious activity where an attacker uses lightweight script-based tools to perform credential harvesting or theft of cryptocurrency assets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects potentially malicious LDAP queries logged by Windows Server 2025 (Event IDs 3039/3040). The rule monitors for common attacker reconnaissance techniques, including Kerberoasting, AS-REP roasting, delegation abuse, AD CS enumeration, and BloodHound-style data collection patterns.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
15 days ago
000
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
104
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
004
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
000
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
000
This rule detects when the MpDlpService.exe process loads the 'mpclient.dll' library from a location other than the legitimate Windows Defender program directories. This behavior is indicative of potential DLL side-loading or hijack execution flow attempts targeting the Microsoft Data Loss Prevention service.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
000
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
000
This rule detects malicious activity related to the exploitation of MpDlpService.exe. It looks for the execution or presence of known malicious file hashes associated with this threat, including a P-stage script, payload files, and a malicious mpclient.dll. Additionally, it identifies instances where the legitimate MpDlpService.exe binary is executed from a non-standard, suspicious directory, which is a common indicator of side-loading or persistence techniques.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
000
This rule detects when the MpDlpService.exe process loads the 'mpclient.dll' library from a location other than the legitimate Windows Defender program directories. This behavior is indicative of potential DLL side-loading or hijack execution flow attempts targeting the Microsoft Data Loss Prevention service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
This rule detects potential staging activity for ClickFix or Vidar malware campaigns. It identifies the creation of files or folders in directories mimicking Windows Diagnostics infrastructure (WDI) or known payload paths, correlated with the execution of suspicious PowerShell commands or archive-related utilities within a 30-minute window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
This rule monitors network, DNS, and HTTP activity to identify connections to known infrastructure associated with the ClickFix social engineering campaign and Vidar infostealer malware. The rule correlates device network events, HTTP request events, and DNS queries against a list of known malicious domains, IP addresses, and URL patterns used for C2, staging, and lures.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
This rule detects malicious activity related to the exploitation of MpDlpService.exe. It looks for the execution or presence of known malicious file hashes associated with this threat, including a P-stage script, payload files, and a malicious mpclient.dll. Additionally, it identifies instances where the legitimate MpDlpService.exe binary is executed from a non-standard, suspicious directory, which is a common indicator of side-loading or persistence techniques.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
004
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
004
Detects process and file creation activity matching known MovieReaper loader and downstream module file hashes (MD5/SHA256). C2 IP/domain network indicators for this campaign require a separate network_connection-category rule, since Sigma logsource categories cannot be mixed within a single rule.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
104
Page 213 of 1871