Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of PowerShell with suspicious command-line arguments and obfuscation techniques commonly used by attackers to execute malicious code, including base64 encoded commands, bypass of execution policies, dynamic assembly loading, and caret-based obfuscation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
103
Detects anomalous remote access or VPN login activity for a user account, characterized by either logins from multiple distinct countries or logins occurring during off-hours (between 8:01 PM and 5:59 AM). This rule helps identify potential credential abuse where valid accounts are being leveraged from unexpected locations or times.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
103
Detects the execution of the Windows Recovery Environment Configuration Tool (REAgentC.exe) with the '/disable' argument. Adversaries may use this command to inhibit system recovery, preventing users from using built-in Windows recovery options during or after a malicious event.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects attempts to clear Windows event logs using built-in utilities such as wevtutil.exe or PowerShell cmdlets (Clear-EventLog, Clear-WinEvent). Adversaries often perform this action to remove traces of malicious activity from the system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the use of the native Windows reg.exe utility to save the Security Account Manager (SAM) registry hive to a file. This technique is commonly used by adversaries to perform offline credential extraction or to dump local account password hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects Microsoft Office applications (Word, Excel, PowerPoint) spawning common LOLBAS (Living Off the Land Binaries and Scripts) child processes. This behavior is a common indicator of macro-based malware or malicious document exploitation where Office applications are used to execute shell commands or scripts for payload delivery or execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the execution of 'git checkout' commands involving 'FETCH_HEAD', initiated by Gemini or Node.js runtime environments. This pattern may indicate automated repository synchronization, potential software supply chain activity, or anomalous usage of developer tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects processes requesting specific access rights to the Local Security Authority Subsystem Service (LSASS) process, which are commonly associated with credential dumping techniques. The rule filters out known security software that performs legitimate LSASS inspection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects instances where AI-assisted coding tools (such as Claude, Copilot, or Gemini) initiate Git operations (clone, checkout, fetch) in a non-interactive context. This behavior may indicate an automated process using AI tools to perform code repository interactions that should typically be user-initiated or are otherwise suspicious in a non-interactive environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the creation or start of the PSEXESVC service, which is a characteristic behavior of the PsExec tool used for remote execution and lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
This rule monitors for potential Kerberos Golden Ticket attacks by detecting specific indicators within Windows security events. It identifies Event ID 4769 with a PAC validation failure status (0x1F), and the use of weak RC4 encryption (0x17) in either TGT requests (Event ID 4768) or service ticket requests (Event ID 4769). These behaviors are often associated with forged Kerberos tickets where the attacker may be using weak encryption or malformed PAC data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the execution of the Windows cipher.exe utility with the '/w' flag from the command prompt. The '/w' flag is used to overwrite free space on a disk, which is a technique often used by adversaries to perform data destruction or hinder forensic recovery of deleted files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects Kerberos TGS (Service Ticket) requests utilizing the insecure RC4 encryption type (0x17). This pattern is a hallmark of Kerberoasting, where an attacker requests service tickets for SPNs in an attempt to crack the service account credentials offline.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects Git command line executions involving 'branch', 'checkout', or 'push' operations that reference what appear to be full commit hashes as branch references. The rule flags instances where 'refname is ambiguous' warnings are generated, which may indicate an attempt to manipulate or interact with git repositories in ways that conflict with existing branches, potentially suggesting malicious repository tampering or discovery activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects high-frequency failed RDP authentication attempts (Windows Event ID 4625 with LogonType 10) originating from the same source. This pattern is indicative of brute-force or credential guessing attacks against Remote Desktop Services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
This rule detects the creation of .lnk files within the Windows Startup directory. Attackers frequently use this persistence technique to ensure that a malicious script or executable runs automatically upon user login.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
103
Detects the execution of MeshAgent or mvtcs (MeshCentral) binaries, which are commonly used for legitimate remote management but can also be used as unauthorized remote access tools by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects execution of PowerShell or Command Prompt where the command line contains obfuscated indicators or specific suspicious files and IP addresses, while simultaneously bypassing the execution policy. This is characteristic of malicious script execution or payload delivery attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects execution of PowerShell or CMD commands originating from Windows Explorer (explorer.exe) that exhibit characteristics of malicious command-line obfuscation, such as encoded commands, bypass flags, or caret-based character obfuscation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
103
This rule detects the creation of specific shortcut files (.lnk) within the Windows Startup folder and monitors for the usage of WScript.Shell to interact with the Startup directory. This behavior is commonly associated with persistence mechanisms where an adversary attempts to automatically execute malicious code upon user login.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
203
Detects the installation or service creation of 'gdrv.sys', a known vulnerable GIGABYTE driver often abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to escalate privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Page 219 of 1871