Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects anomalous network connections initiated by a node.exe process spawned by npm.exe within 2 minutes of a lifecycle script (preinstall or postinstall) execution. This behavior is indicative of malicious dependency installation where a compromised package attempts to exfiltrate data or fetch additional payloads immediately upon installation.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
003
Detects anomalous network connections initiated by a node.exe process spawned by npm.exe within 2 minutes of a lifecycle script (preinstall or postinstall) execution. This behavior is indicative of malicious dependency installation where a compromised package attempts to exfiltrate data or fetch additional payloads immediately upon installation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
003
Detects anomalous network connections initiated by a node.exe process spawned by npm.exe within 2 minutes of a lifecycle script (preinstall or postinstall) execution. This behavior is indicative of malicious dependency installation where a compromised package attempts to exfiltrate data or fetch additional payloads immediately upon installation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
003
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
504
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
16 days ago
000
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
16 days ago
000
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
This rule detects modifications to the security descriptors (ACLs) of sensitive Active Directory objects, specifically targeting additions of powerful rights like GenericAll, GenericWrite, WriteDacl, or ForceChangePassword. Monitoring these changes on privileged objects such as Domain Admins, Enterprise Admins, and Domain Controllers is critical for detecting potential privilege escalation or persistence efforts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
5020
Detects the assignment of SeDebugPrivilege or SeImpersonatePrivilege to a non-SYSTEM account, followed by the execution of a new process from common service parents (spoolsv.exe, w3wp.exe, dllhost.exe) within the same logon session. This behavior is indicative of privilege escalation attempts using local potato-style exploits (e.g., PrintSpoofer, JuicyPotato) that leverage service tokens for impersonation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the execution of control.exe or rundll32.exe with command line arguments pointing to .cpl files located in non-standard, user-writable directories such as Temp, AppData, Downloads, or Users/Public. This is a common technique used by adversaries to proxy execution of malicious payloads while bypassing standard path restrictions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects execution of the Microsoft .NET utility InstallUtil.exe with command-line arguments typically used to execute arbitrary code or bypass application whitelisting. The rule monitors for common bypass switches such as /logfile, /LogToConsole=false, or /U, while filtering out executions from standard Windows directories to identify potential malicious usage of this signed binary proxy.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the execution of Regsvcs.exe or Regasm.exe, which are trusted Windows .NET binaries, from non-standard or user-writable directories (such as Temp, AppData, Downloads, or User profiles). Adversaries often abuse these binaries to proxy the execution of arbitrary malicious code (DLLs) by bypassing application control policies.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects unauthorized access or decryption attempts related to Group Policy Preferences (GPP) files stored in SYSVOL. Adversaries often target these XML files to extract embedded 'cpassword' attributes, which can be decrypted using publicly known keys to obtain plain-text administrative credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects outbound network connections to known Tor SOCKS (9050, 9150) or OR (9001, 9051) ports initiated by processes other than standard, authorized Tor client binaries. This is indicative of potential C2 traffic obfuscation or unauthorized use of the Tor network within the environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
Page 223 of 1871