Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects outbound network connections from internal devices to a set of known malicious IP addresses (45.151.45.31 and 46.166.79.31) which may indicate command and control communication or other malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
22 days ago
103
This rule monitors for file and process creation events associated with known FeralWolf threat actor malware, including MQTTDoor, MatrixDoor, RDPSocksProxy, GenieLocker ransomware, fscan, and tools leveraging CVE-2026-31431.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
003
Detects the execution of processes with 'revsocks' in the file name. Revsocks is a known proxy tool often utilized by threat actors for establishing reverse SOCKS proxies, facilitating command and control communication, and bypassing network segmentation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
003
Detects the execution of PowerShell commands that reference the 'nyx' script from 'raw.githubusercontent.com', combined with common download and execution patterns such as 'Invoke-Expression' or 'Invoke-WebRequest'. This activity is consistent with retrieving and executing remote post-exploitation scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
003
Detects evidence of potential credential dumping from the Local Security Authority Subsystem Service (LSASS) process. The rule monitors for two distinct behaviors: the use of MemProcFS with device memory access flags targeting a RAW file, and the creation of files containing 'lsass.exe', 'minidump', and 'readme.txt' in their paths or filenames, which is characteristic of certain post-exploitation toolkits that harvest LSASS memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
003
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
21042
Detects the execution of pythonw.exe spawned by ComputerDefaults.exe, which is a known technique for bypassing User Account Control (UAC) to achieve elevated privileges. This rule specifically tracks instances where a Python script is initiated and subsequently triggered by the UAC-bypassing binary within a 5-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the creation of a scheduled task using the 'schtasks.exe' utility where the task name is 'MultiUpdater' and the task definition is imported from a file with a specific naming convention and extension (mgk, tmp, or xml) in the root directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the execution of rundll32.exe with a command line referencing a DLL file stored in the C:\ProgramData directory. This pattern is commonly used by adversaries to execute malicious code while masquerading as legitimate system activity, particularly when initiated by command shell or browser processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects a sequence of suspicious activities associated with credential dumping and inhibiting system recovery. The rule tracks when a user account executes multiple commands related to volume shadow copies (vssadmin, rmdir, mklink) or attempts to copy sensitive registry files (SAM, SYSTEM, SECURITY) within a 15-minute window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects a sequence of suspicious process executions related to the 'RemoteAgent' application, specifically monitoring for MSI-based installations, NSSM service management, and API checks across a device. The rule aggregates distinct process events per device and flags if two or more distinct indicators are identified within a 14-day window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects unexpected child process execution spawned by the ScreenConnect ClientService. This activity is indicative of the exploitation of CVE-2026-84869, which allows for unauthorized file transfer and arbitrary code execution within the context of the remote support agent without requiring user interaction or confirmation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects activity associated with a potential RMM (Remote Monitoring and Management) agent communicating with known malicious infrastructure and accessing sensitive files like credentials or IDs. This often indicates an adversary leveraging legitimate RMM tooling for post-compromise activity or exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects post-exploitation shell activity spawned from the IIS worker process (w3wp.exe), narrowed to command lines carrying encoded/obfuscated PowerShell flags, remote-download cradles, or basic recon/persistence commands (whoami, certutil, bitsadmin, schtasks, reg add). This reduces noise from benign w3wp.exe-initiated automation while retaining the behavioral pattern seen in the Telerik UI for ASP.NET AJAX unauthenticated RCE chain (webshell/in-memory DLL execution dropping to a shell).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
26 days ago
509
This rule detects the creation of a scheduled task using an XML definition located in the user's AppData\Local\Temp directory, which is a common staging location for malware. This event is correlated with subsequent high-frequency, short-lived execution of pythonw.exe using .pyw scripts, characteristic of automated implant persistence and re-launch mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects a sequence of events consistent with credential dumping of sensitive Windows registry hives (SAM, SYSTEM, SECURITY). The attack involves querying shadow copies using vssadmin, creating a symbolic link to the shadow copy volume via mklink, and copying the hive files from that location. Cleanup attempts using rmdir are also monitored.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects unauthenticated attempts to exploit CVE-2025-3248 in the Langflow 'validate/code' endpoint, characterized by missing authentication headers and the presence of suspicious Base64-encoded payloads or command execution keywords. Additionally, it identifies potential post-exploitation activity where Langflow processes spawn Python subprocesses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
004
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
004
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
104
This rule detects the execution of npm or node.js commands involving specific, potentially malicious package names or internal project naming patterns often associated with dependency confusion or supply chain attacks. It monitors npm/node CLI arguments for targeted library names or installation commands that deviate from standard organizational behavior.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
003
Page 222 of 1871