Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the presence of known artifacts associated with the GhostContainer backdoor, including indicators of Neo-reGeorg web shell usage, ysoserial payloads, and exploitation attempts targeting the CVE-2020-0688 vulnerability via VIEWSTATE manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
This rule monitors for suspicious activity originating from the WinRM service host (wsmprovhost.exe). It detects when command shells (cmd.exe, powershell.exe) are spawned by WinRM with known malicious command-line arguments (e.g., Evil-WinRM tools), monitors for the creation of potentially malicious configuration files (e.g., config.toml), and identifies established network connections to common WinRM ports (5985/5986) to detect unauthorized remote sessions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects a sequence of events consistent with credential dumping of sensitive Windows registry hives (SAM, SYSTEM, SECURITY). The attack involves querying shadow copies using vssadmin, creating a symbolic link to the shadow copy volume via mklink, and copying the hive files from that location. Cleanup attempts using rmdir are also monitored.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects a multi-stage installation of the Level RMM agent. This rule monitors for a correlation of events including the execution of 'LevelInstaller.exe' with specific installation arguments, file drops in potentially spoofed vendor paths (Dell or Level), the creation of a 'Level' service, and the addition of a 'Level Watchdog' scheduled task on the same device within a 24-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects potential lateral movement or pivot attempts by correlating repeated failed RDP logons (RemoteInteractive) against sensitive targets (Domain Controllers, File Servers, Backup Servers) with concurrent security tool blocks (e.g., Microsoft Defender Antivirus, Exploit Guard) on the originating beachhead device within a 4-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects a sequence of suspicious process executions related to the 'RemoteAgent' application, specifically monitoring for MSI-based installations, NSSM service management, and API checks across a device. The rule aggregates distinct process events per device and flags if two or more distinct indicators are identified within a 14-day window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
This rule detects the creation of a scheduled task using an XML definition located in the user's AppData\Local\Temp directory, which is a common staging location for malware. This event is correlated with subsequent high-frequency, short-lived execution of pythonw.exe using .pyw scripts, characteristic of automated implant persistence and re-launch mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the creation of a scheduled task using the 'schtasks.exe' utility where the task name is 'MultiUpdater' and the task definition is imported from a file with a specific naming convention and extension (mgk, tmp, or xml) in the root directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the execution of PowerShell with command-line arguments that suggest programmatically capturing or redirecting console output using ScriptBlock techniques (Create, Console, In, ReadToEnd). This pattern is often associated with obfuscated script execution, in-memory payloads, or attempts to bypass logging by capturing output via .NET streams.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the execution of rundll32.exe with a command line referencing a DLL file stored in the C:\ProgramData directory. This pattern is commonly used by adversaries to execute malicious code while masquerading as legitimate system activity, particularly when initiated by command shell or browser processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects network activity characteristic of the CVE-2019-0708 (BlueKeep) Remote Desktop Services exploit, including specific RDP negotiation patterns and subsequent RDP service crashes or resets potentially indicative of a successful or failed exploitation attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects a sequence of suspicious activities associated with credential dumping and inhibiting system recovery. The rule tracks when a user account executes multiple commands related to volume shadow copies (vssadmin, rmdir, mklink) or attempts to copy sensitive registry files (SAM, SYSTEM, SECURITY) within a 15-minute window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects activity associated with a potential RMM (Remote Monitoring and Management) agent communicating with known malicious infrastructure and accessing sensitive files like credentials or IDs. This often indicates an adversary leveraging legitimate RMM tooling for post-compromise activity or exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects instances where browser processes (Chrome or Edge) are spawned by smartscreen.exe and subsequently access sensitive browser storage files such as Login Data, Cookies, or Local State. This pattern is indicative of a process injection or masquerading chain used to extract credentials or session data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects instances where Python interpreters (python.exe or pythonw.exe) are executed from a subdirectory within ProgramData that matches a 32-hex character pattern, initiated by the 7zip archive utility (7za.exe). This pattern is indicative of a self-extracting archive or malicious installer unpacking and executing Python scripts in a stealthy, non-standard location.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects anomalous process execution originating from the PaperCut application server process, specifically targeting the SetupCompleted servlet endpoint. This pattern is indicative of an exploitation attempt, such as CVE-2026-81578, where unauthenticated requests trigger backend server actions before proper access validation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects the execution of common command-line or scripting interpreters (cmd, powershell, cscript, etc.) spawned by the ScreenConnect remote administration client. This is a common pattern used by attackers leveraging legitimate remote access tools for post-exploitation activities and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
204
This rule detects the execution of the Rubeus tool, a known C# toolkit for raw Kerberos interaction. The rule specifically alerts on command-line arguments associated with common Kerberos attacks such as Kerberoasting, requesting TGT/TGS tickets, and performing Pass-the-Ticket operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
104
Detects the creation or modification of specific system driver files (nvfsflt64.sys, Alinubx.sys) combined with the installation or initiation of a Windows service associated with NVIDIA filter names. This behavior is often indicative of persistence mechanisms, potential rootkit activity, or the deployment of vulnerable drivers (BYOVD).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
22 days ago
003
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
003
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
Page 220 of 1871