Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects anomalous service principal activity characterized by multiple, rapidly issued, and overlapping OAuth tokens within a short time window. This pattern is associated with automated/agentic token orchestration (e.g., JADEPUFFER/Storm-3168 campaign) rather than standard manual operator activity, specifically when leveraging the python-requests user agent.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
Detects the execution of PowerShell scripts located in Windows temporary directories (AppData/Local/Temp or Temp) that utilize common evasion flags such as hidden window style, bypass execution policy, or non-interactive mode. This behavior is frequently associated with initial stagers, droppers, or malicious script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
006
Detects the loading of specific DLL files (winfsp-x64.dll or DukeQt.dll) where the loading process or the DLL file location originates from outside the legitimate system directory (C:\Windows\). This behavior is often associated with DLL sideloading or search order hijacking where a malicious actor places a DLL in an untrusted directory to be loaded by a legitimate application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
103
Detects the modification or creation of a 'loginwindow.plist' file within the '/Library/LaunchAgents/' directory, correlated with a process containing 'renderer' and 'launchctl' or 'LaunchAgents' in its command line. This pattern suggests potential persistence mechanisms being established by a renderer process (e.g., an Electron-based application or browser process).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
006
Detects UNC6240 PSEMHUB.war web shell/tunnel/trojanized installer artifacts by distinctive content markers (x.jsp, u.jsp, tunnel.jsp/jspx, Ple64.exe)
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
001
Detects outbound network connections from internal devices to a set of known malicious IP addresses (217.156.122.129, 37.221.66.43) across commonly abused command-and-control ports (8080, 3480, 9998, 9999, 4444).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
19 days ago
7018
This rule detects activity involving known malicious indicators of compromise (IOCs), including specific IP addresses, domains, and file hashes. It monitors network connections, file system activity, process execution, and email attachments, filtering out common security tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects activity involving known malicious indicators of compromise (IOCs), including specific IP addresses, domains, and file hashes. It monitors network connections, file system activity, process execution, and email attachments, filtering out common security tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects activity involving known malicious indicators of compromise (IOCs), including specific IP addresses, domains, and file hashes. It monitors network connections, file system activity, process execution, and email attachments, filtering out common security tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects Bitsadmin connections to domains with uncommon TLDs
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
6 days ago
000
This rule detects potential persistence via scheduled tasks that masquerade as legitimate network components (e.g., 'System Health Monitor'), as well as abnormal use of WebDav via rundll32.exe or net.exe in the context of the Star Blizzard (COLDRIVER) campaign. It monitors for task creation/updates, schtasks command lines, registry artifacts related to task scheduling, and suspicious WebDav network utility usage, while excluding common security tool processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects potential persistence via scheduled tasks that masquerade as legitimate network components (e.g., 'System Health Monitor'), as well as abnormal use of WebDav via rundll32.exe or net.exe in the context of the Star Blizzard (COLDRIVER) campaign. It monitors for task creation/updates, schtasks command lines, registry artifacts related to task scheduling, and suspicious WebDav network utility usage, while excluding common security tool processes.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
This rule detects potential persistence via scheduled tasks that masquerade as legitimate network components (e.g., 'System Health Monitor'), as well as abnormal use of WebDav via rundll32.exe or net.exe in the context of the Star Blizzard (COLDRIVER) campaign. It monitors for task creation/updates, schtasks command lines, registry artifacts related to task scheduling, and suspicious WebDav network utility usage, while excluding common security tool processes.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000