Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects successful authentication events for remote access applications (VPN, RDP, Azure AD App Proxy) where the source IP address or ASN has not been observed in the user's login history within the preceding 14 days. This behavior is indicative of potential account takeover using compromised credentials sourced from infostealers or other credential-harvesting activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects various process injection techniques (such as CreateRemoteThread, QueueUserAPC, and remote memory writes) initiated by external processes targeting high-value, commonly abused Windows system processes like svchost.exe, lsass.exe, and explorer.exe. These techniques are often used by ransomware and other malware to hide malicious code execution within trusted system memory space.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects high-volume file rename and modification operations occurring across multiple directories, combined with the creation of files indicative of ransom notes (e.g., readme, decrypt, how-to-restore). This pattern is strongly associated with the encryption phase of a ransomware attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects various methods used by adversaries to perform credential dumping from the Local Security Authority Subsystem Service (LSASS) process. It monitors for direct process access with suspicious handle permissions, the use of comsvcs.dll via rundll32.exe for MiniDump creation, the execution of memory dumping tools like procdump, and the creation of LSASS memory dump files by Task Manager.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of scheduled tasks using schtasks.exe or PowerShell cmdlets that execute with SYSTEM privileges, or tasks that reference common temporary directories or persistence triggers (logon, idle). This behavior is frequently associated with ransomware, malware persistence, or staged payload execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of PowerShell with encoded command arguments (e.g., -enc, -EncodedCommand) combined with common web-request cmdlets or download-cradle patterns (e.g., IEX, Net.WebClient, Invoke-WebRequest). This pattern is frequently used by adversaries to execute obfuscated remote payloads in memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a suspicious burst of commands commonly used to disable security services, antivirus, or backup agents on a single host. The rule monitors for a high frequency of taskkill, net stop, sc stop, or PowerShell Stop-Service operations targeting a predefined list of sensitive security software process and service names within a short timeframe, which is a common precursor to ransomware encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects attempts by an adversary to disable or clear Windows Event logs using standard administrative utilities such as wevtutil, PowerShell, auditpol, net, sc, or wmic to cover tracks or hinder forensic analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of common enumeration tools and commands often associated with ransomware-precursor behavior. This includes the use of AdFind, dsquery, net.exe, and nltest for domain account, group, and trust discovery, as well as the execution of BloodHound/SharpHound collection activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects persistence attempts via Windows Registry run keys and Startup folders. The rule identifies suspicious modifications to run/runonce registry keys involving common user-writable paths (e.g., Temp, AppData) or the execution of PowerShell commands with common obfuscation flags (e.g., -enc). Additionally, it detects the creation of executable files (.lnk, .ps1, .vbs, .bat) within user Startup folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects persistence attempts via Windows Registry run keys and Startup folders. The rule identifies suspicious modifications to run/runonce registry keys involving common user-writable paths (e.g., Temp, AppData) or the execution of PowerShell commands with common obfuscation flags (e.g., -enc). Additionally, it detects the creation of executable files (.lnk, .ps1, .vbs, .bat) within user Startup folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects potential lateral movement by identifying processes spawned via WMI (e.g., wmic.exe, WmiPrvSE.exe) or PowerShell Remoting (WinRM, Invoke-Command, Enter-PSSession) that occur shortly after a successful network or remote interactive logon on the same host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects the deployment of suspicious executables or scripts (e.g., .exe, .bat, .ps1, .vbs) via Group Policy (GPO) paths or through GPO-related processes like gpscript.exe and gpupdate.exe. This activity is consistent with using GPOs to distribute and execute malicious binaries across a domain, often a precursor to ransomware deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the deletion of Windows Volume Shadow Copies using vssadmin.exe, wmic.exe, or PowerShell (WMI/CIM objects). This activity is commonly used by ransomware to prevent local data recovery by destroying shadow copy backups before encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the deletion of Windows Volume Shadow Copies using vssadmin.exe, wmic.exe, or PowerShell (WMI/CIM objects). This activity is commonly used by ransomware to prevent local data recovery by destroying shadow copy backups before encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects attempts to clear Windows Event Logs using either the native 'wevtutil.exe' utility or PowerShell cmdlets 'Clear-EventLog' and 'Remove-EventLog'. Adversaries often perform this action to remove evidence of their presence or malicious activities from a compromised system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of known Remote Monitoring and Management (RMM) tools from common staging directories (e.g., Temp, Downloads, AppData) or using command-line arguments indicative of a silent or hidden installation, which is a common pattern for initial access and persistence by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the use of command-line tools like s5cmd or aws-cli to synchronize or copy data to an Amazon S3 bucket. The rule identifies suspicious patterns by looking for specific transfer commands combined with recursive or high-concurrency flags that indicate mass data movement often associated with exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized attempts to access sensitive Veeam Backup and Replication credentials by querying the backend SQL database or directly accessing DPAPI Master Key files. This activity is indicative of an attacker attempting to decrypt backup credentials stored by the Veeam service.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of scheduled tasks using 'schtasks.exe' or 'Register-ScheduledTask' where the task command path is located in suspicious directories such as AppData, Temp, or ProgramData, or where the task is configured to run under the SYSTEM account. This behavior is commonly used by adversaries for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000