Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects the execution of the Rubeus tool, a known C# toolkit for raw Kerberos interaction. The rule specifically alerts on command-line arguments associated with common Kerberos attacks such as Kerberoasting, requesting TGT/TGS tickets, and performing Pass-the-Ticket operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
104
Detects the creation or modification of specific system driver files (nvfsflt64.sys, Alinubx.sys) combined with the installation or initiation of a Windows service associated with NVIDIA filter names. This behavior is often indicative of persistence mechanisms, potential rootkit activity, or the deployment of vulnerable drivers (BYOVD).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
22 days ago
003
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
003
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
003
Detects instances where explorer.exe initiates cmd.exe with suspicious command-line patterns often associated with malicious script execution or evasion. These include caret-based obfuscation, mixed-case PowerShell invocations, or base64-like blobs, alongside indicators of common malicious file paths or execution policy bypass flags.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
003
This rule detects instances where a process associated with a known StealC command-and-control (C2) IP address subsequently spawns a hidden cmd.exe instance. It correlates network connections to known malicious infrastructure with the creation of hidden command shells within the same device session, specifically looking for common parent processes like web browsers or system utilities.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
003
This rule detects instances where a process associated with a known StealC command-and-control (C2) IP address subsequently spawns a hidden cmd.exe instance. It correlates network connections to known malicious infrastructure with the creation of hidden command shells within the same device session, specifically looking for common parent processes like web browsers or system utilities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
103
This rule monitors for potential MeshAgent activity associated with the Settra threat actor. It identifies processes that are likely renamed instances of MeshAgent (via metadata inspection), processes attempting to communicate with known C2 IP addresses, and direct network connections to these C2 IP addresses.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
203
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
003
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
203
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
003
This rule detects the presence, installation, or execution attempts of the known vulnerable GIGABYTE driver (gdrv.sys). Monitoring for this specific driver is a common practice to identify attempts to perform 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, which can be used for kernel-mode code execution and privilege escalation.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
003
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
003
This rule detects potential ransomware activity by correlating three distinct events: the execution of a suspicious, potentially obfuscated binary (matching a specific naming pattern of _win64.exe) from an untrusted location (e.g., Temp, AppData, Downloads), followed by a high volume of file modifications or renames with specific ransomware-related extensions (.locked), and the dropping of a known ransom note file (RESTORE_FILES.txt) within a short 15-minute time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
003
Detects a network activity pattern from a single host characterized by a high volume of connections to a wide range of remote hosts and ports, combined with an exceptionally low coefficient of variation in inter-request timing. This pattern is indicative of an automated, scriptable agent or AI-driven reconnaissance tool rather than a human-operated scanner, likely performing automated asset discovery or network enumeration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the installation or execution of virtual camera or synthetic media software followed shortly by the launch of common video conferencing applications on the same endpoint. This behavior may indicate an attempt to inject synthetic video feeds into meetings for impersonation or business email compromise (BEC) attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of high-privilege administrative, firewall, or file-system commands by processes identified as autonomous agent runtimes (e.g., LangChain, AutoGPT) or Robotic Process Automation (RPA) tools. This rule surfaces potential unauthorized infrastructure changes or automated abuse by agents when direct change management validation is absent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects a single source IP address rapidly attempting connections to multiple distinct devices and ports within a short time window. This behavior is indicative of an automated agent or scanner performing reconnaissance and potentially attempting to chain exploitation across multiple targets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects potential exploitation of AI agent frameworks, such as Semantic Kernel, where plugin or tool invocation primitives are abused to execute arbitrary commands or manipulate files via path traversal. The rule monitors for AI-hosting processes (e.g., python.exe, node.exe) spawning shell child processes or file-related commands containing path traversal sequences (e.g., '..\..\') paired with file operation keywords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Page 221 of 1871