Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the use of 'vim-cmd' or 'esxcli' to power off or terminate virtual machine processes on an ESXi host, which may indicate malicious activity such as ransom-related VM shutdown or service disruption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of new administrator or technician accounts within the SimpleHelp Remote Monitoring and Management (RMM) platform via API calls. This activity is often associated with unauthorized persistence creation by an adversary who has gained access to the platform.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a process obtaining handle access to the LSASS process (Sysmon Event ID 10) followed by the creation of a file (Sysmon Event ID 11) using an extension other than '.dmp'. This behavior is characteristic of adversaries attempting to obfuscate credential dumping activities by bypassing simple extension-based detection rules.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects web application server processes (such as IIS, Apache, Tomcat, Java, Nginx, or Node.js) spawning command-line interpreters or system utilities. This behavior is frequently associated with webshell execution or post-exploitation activities following the exploitation of a public-facing application, often seen in VPN or enterprise software compromises.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of files commonly associated with ransomware notes (e.g., README.txt, HOW_TO_DECRYPT.txt) across multiple directories, which is a strong indicator of the impact phase where files have been encrypted and the adversary is providing recovery instructions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous authentication behavior originating from a single source IP targeting an SSL VPN gateway. The rule identifies a high volume of unique usernames failing authentication within a short time window, a pattern indicative of password spraying and often associated with initial access attempts on environments lacking multi-factor authentication (MFA), such as those leveraged in Akira ransomware operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the use of the bcdedit.exe utility to configure the Windows boot configuration to enter Safe Mode (minimal or with networking), immediately followed by the execution of a shutdown command with the reboot flag. This sequence is a known technique utilized by Akira ransomware affiliates to force a system reboot into a restricted environment where security agents and endpoint detection and response (EDR) tools may fail to load, allowing for undetected encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a burst of lateral movement activity characterized by the use of administrative tools like PsExec or NetExec/CrackMapExec to execute commands or services on multiple distinct target hosts from a single source host within a short window. This pattern is commonly associated with ransomware affiliates or threat actors performing reconnaissance and mass deployment of malicious payloads prior to encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects remote command execution patterns associated with the Impacket suite (e.g., wmiexec.py, atexec.py, smbexec.py). The detection identifies cmd.exe processes spawned by WmiPrvSE.exe or svchost.exe that contain specific command-line arguments indicative of Impacket's remote execution behavior, such as output redirection to hidden administrative shares or temporary files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of rclone.exe or renamed binaries with command-line flags indicative of data exfiltration to cloud storage providers such as S3, Mega, OneDrive, or Google Drive. This behavior is frequently associated with ransomware actors, including Akira, Qilin, and Storm-2570, who use Rclone to perform mass exfiltration of sensitive file share data prior to encryption (double extortion).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects attempts to clear Windows event logs using built-in utilities like wevtutil.exe, PowerShell commands (Clear-EventLog, Remove-EventLog), or the detection of Event ID 1102 (Log cleared). This activity is commonly used by adversaries, including ransomware affiliates, to obfuscate their tracks during or after an attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized attempts to dump credentials from the Local Security Authority Subsystem Service (LSASS) process. This includes the execution of known credential-harvesting tools (e.g., Mimikatz, LaZagne, pypykatz), the use of system utilities like procdump and comsvcs.dll to dump process memory, and anomalous direct handle access to lsass.exe by non-system processes. This activity is associated with Storm-2570 post-compromise tradecraft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects Active Directory Directory Replication Service (DRSUAPI) GetNCChanges requests originating from a principal or host that is not recognized as a Domain Controller. This behavior is indicative of unauthorized DCSync operations used to dump NTDS.dit hashes, a common technique for credential harvesting associated with ransomware actors like Qilin.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of reconnaissance commands designed to enumerate Active Directory domain trust relationships. Attackers, including those associated with ransomware operations like INC Ransom, use these tools to map organizational structures and identify pathways for lateral movement and cross-domain propagation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the execution of reconnaissance commands designed to enumerate Active Directory domain trust relationships. Attackers, including those associated with ransomware operations like INC Ransom, use these tools to map organizational structures and identify pathways for lateral movement and cross-domain propagation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the creation of scheduled tasks using schtasks.exe that exhibit behaviors associated with common remote execution tools (e.g., Impacket's atexec.py) or staging from insecure directories like Temp, ProgramData, or network shares. These patterns are frequently used by threat actors, including INC Ransom, for lateral movement and remote execution of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a multi-stage extortion tactic where a host is targeted by a mass creation of initial decryption-style ransom notes across multiple directories, followed by a subsequent drop of distinct follow-up 'press release' or 'threat' notes within a 30-minute window, indicative of INC Ransom behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized modification or creation of registry keys under HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\ to maintain persistence for remote access/RMM tools during Safe Mode with Networking. This technique is used by Akira ransomware affiliates to evade EDR and security software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects behavioral patterns associated with the Everest ransomware loader, specifically the execution of a .NET host process from a non-standard parent, potentially indicating process injection, combined with network activity indicative of lateral movement or discovery, such as Wake-on-LAN packets or SMB scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects usage of the 'gem' command (install, build, push, publish) that includes naming patterns or specific command strings associated with the GemStuffer supply chain compromise campaign. This targets attempts to introduce malicious dependencies into the environment using RubyGems.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
20 days ago
6024
This rule detects the loading of the 'vsstrace.dll' module by processes that are not standard system processes or authorized software. The 'vsstrace.dll' is a library used by the Volume Shadow Copy Service (VSS). Unauthorized or unexpected processes loading this DLL may indicate an attempt to interact with or manipulate volume shadow copies, which is a common behavior for ransomware attempting to inhibit system recovery.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
15 days ago
106