Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects high-frequency, automated interactions with popular AI assistant web interfaces (e.g., Gemini, Perplexity, Claude, Copilot) from common browser processes. This pattern often indicates unauthorized automated data submission or scraping, which may follow or facilitate automated exfiltration of browser-resident data.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
205
This rule detects potential exploitation attempts targeting VLC media player, specifically focusing on the CVE-2026-56711 integer overflow vulnerability. The rule identifies instances where VLC processes a PNG file originating from untrusted locations (such as Downloads, Temp, or removable media) shortly after that file was created or modified on the host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
2016
In DeviceNetworkEvents, we can find both JA4 and JA4S inside AdditionalFields for some TLS connections. This is interesting because we can look at both sides of the same TLS communication. We can compare clients, servers and JA4/JA4S combinations, and look for patterns or connections that behave differently from what we normally see. The following KQL extracts and decodes both fingerprints from the same network event.
avatar
Sergio Albea@Sergio_Albea
avatar
01 | 🇨🇭 Swiss Cyber Hunters
26 days ago
4110
This rule detects potentially malicious child processes spawned by processes associated with Microsoft Semantic Kernel agents. These agents may be exploited to execute administrative tools, living-off-the-land binaries (LOLBins), or networking utilities commonly used in post-exploitation activities, such as credential dumping, discovery, or command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects the initiation of the OAuth 2.0 Device Authorization Grant flow via command-line arguments within standard web browsers. This flow is frequently exploited in phishing campaigns to obtain unauthorized access tokens by tricking users into entering a device code on a malicious or attacker-controlled authorization page.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
104
Detects the presence of prompt-injection framing and malicious intent instructions within the first few lines of source code files. These strings are designed to deceive LLM-based SAST or code review tools into ignoring, misclassifying, or bypassing security analysis of malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects the creation of a shortcut (.lnk) file by the process 'OrionQuests-Setup.exe'. This activity is often associated with installers or applications placing shortcuts on the desktop or in startup folders for persistence or execution initiation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
104
Detects Kerberos TGS (Ticket Granting Service) requests where the ticket encryption type is RC4 (0x17). This behavior, commonly referred to as Kerberoasting, involves requesting service tickets for accounts with service principal names (SPNs) set, often to perform offline brute-force attacks against the service account's password hash. The rule excludes common service account patterns and machine accounts to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects outbound HTTP/HTTPS POST requests where the URI, query string, or path contains evidence of sensitive credential material, such as AWS access keys, private key blocks, or common environment variable patterns, indicative of potential credential harvesting and exfiltration to an external destination.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects suspicious PE files that masquerade as Mozilla Firefox by using Firefox-related product names and metadata, but lack valid Mozilla Corporation code-signing signatures and are located within the ProgramData directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects the creation of a scheduled task containing the string 'Google Chrome Update' in the command line, where the task is not the legitimate 'GoogleUpdateTaskMachine' task. The rule specifically targets tasks that execute PowerShell or arbitrary executables, which is a common persistence technique used by adversaries to mask malicious tasks as legitimate software updates.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects the execution of PowerShell from a shortcut (.lnk) file, particularly when suspicious command-line arguments such as hidden windows, encoded commands, or bypass flags are utilized. This pattern is commonly associated with initial access via malicious attachments or shortcut files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects suspicious PE files that masquerade as Mozilla Firefox by using Firefox-related product names and metadata, but lack valid Mozilla Corporation code-signing signatures and are located within the ProgramData directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
104
Detects Python processes (python.exe, python3.exe, pythonw.exe) performing DNS resolution for Microsoft identity, device login, or Graph API endpoints. This activity is consistent with automated tooling, such as python-requests, performing device-code flow polling or API token authentication within an environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
This rule detects modifications to the Windows hosts file by unauthorized processes. The hosts file is often targeted by adversaries to redirect network traffic, intercept communications, or prevent access to security-related websites.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects unauthorized write, create, or rename operations on the Windows HOSTS file (\drivers\etc\hosts). The rule excludes common system processes and paths associated with legitimate administrative or update activities, targeting potentially malicious attempts to redirect network traffic by modifying DNS resolution locally.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects instances where PowerShell.exe acts as a parent process or initiator for potentially suspicious process injections into common host processes including csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with code execution or persistence mechanisms where PowerShell injects malicious logic into other processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
003
Detects the use of the wevtutil.exe utility to clear the Microsoft-Windows-Defender/Operational event log, a technique used by adversaries to disrupt security monitoring and hide malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
003
Detects the execution of the MeshCentral remote management agent (meshagent.exe) or processes masquerading as the agent using the known alias 'mvtcs.exe'. This rule identifies the start of these processes to detect unauthorized or potentially malicious remote management activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
003
Detects the execution of PowerShell with suspicious command-line arguments and obfuscation techniques commonly used by attackers to execute malicious code, including base64 encoded commands, bypass of execution policies, dynamic assembly loading, and caret-based obfuscation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
103
Detects anomalous remote access or VPN login activity for a user account, characterized by either logins from multiple distinct countries or logins occurring during off-hours (between 8:01 PM and 5:59 AM). This rule helps identify potential credential abuse where valid accounts are being leveraged from unexpected locations or times.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
103
Page 218 of 1871