Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
001
Detects the installation of a potentially malicious root certificate on a host. The rule monitors for common command-line arguments used by 'certutil.exe' to add certificates to the store, use of the 'security' utility for certificate installation on macOS, and the execution of processes referencing 'Localcertificate.zip'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
204
This rule detects inbound HTTP requests targeting Microsoft Exchange Server that contain the specific headers and patterns associated with the ProxyLogon (CVE-2021-26855) Server-Side Request Forgery (SSRF) vulnerability. It specifically monitors for the presence of the 'X-BEResource' header and malformed request structures used by attackers to bypass authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects instances where Google Chrome accesses the camera or microphone without a preceding browser-based user interaction event (such as a mouse click or user input). This can indicate malicious browser extensions or hijacked processes attempting to surreptitiously capture audio or video.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
304
Detects instances where a web browser process (e.g., Chrome, Edge, Firefox) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently associated with malicious 'ClickFix' or 'fake decryption' social engineering campaigns where users are tricked into copying and executing malicious commands into a terminal.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects the execution of PowerShell with hidden window styles and encoded commands that perform common post-exploitation activities, such as remote file downloading or expression evaluation via IEX. This is a common pattern for fileless malware delivery and secondary payload execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
104
Detects instances where known NetSupport Manager binaries (client32.exe, netsupportmanager.exe, pcicfgnt.exe) are used to perform persistence-related actions, such as creating a new Windows service, adding a scheduled task, or modifying Run/Winlogon registry keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
104
Detects browser-based network requests to 'script.google.com'. This can indicate usage of Google Apps Scripts, which are sometimes abused by attackers for Command and Control (C2) infrastructure, data exfiltration, or as a proxy for malicious payloads, by blending in with legitimate Google traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
104
Detects instances where the IIS worker process (w3wp.exe) spawns common command-line or system utilities often used for post-exploitation activities, specifically when command-line arguments contain references to 'MSExchange' or 'Exchange'. This behavior is frequently associated with exploitation attempts against Microsoft Exchange servers, such as the ProxyLogon chain, where a web shell or other malicious script might be used to execute commands via the IIS process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects the creation of a registry value named 'SnapCart' within the Windows Run keys. Adversaries use Run keys to ensure that malicious programs execute automatically upon user login or system startup, establishing persistence on the compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects the creation of Object Manager symbolic links that redirect the Windows Defender 'WD_SCAN' object to a loopback UNC share path. This behavior is indicative of a symlink exploitation technique (ShieldCrash/CVE-2026-69414) used to manipulate Windows Defender or associated scan operations by redirecting them to an adversary-controlled or loopback-hosted target.
avatar
Arnold Chan@slaz
avatar
Hunters
28 days ago
7015
Detects indicators of the SparroWocky Trident loader, including specific side-loaded DLLs (winfsp-x64.dll, DukeQt.dll), encrypted payload files with custom magic headers, persistence mechanisms such as specific service names and registry keys, inter-process communication objects (mutexes, events, shared memory), and named pipes used for C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects camera or microphone access events triggered by Chrome browser processes associated with AI agent contexts (e.g., Gemini, assistant, side panels, or extensions) where no user gesture or active video conferencing application is detected. This behavior is indicative of unauthorized or surreptitious media device usage by browser-based AI integrations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects the execution of known Remote Monitoring & Management (RMM) software on Windows systems. This behavior is frequently abused by threat actors, including Scattered Spider, to maintain persistent access after gaining control via social engineering or identity-based attacks (e.g., vishing-driven credential or MFA resets).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the installation or configuration of a browser extension that combines 'declarativeNetRequest' (network manipulation) and 'content_scripts' (DOM injection) capabilities while targeting sensitive AI-assistant domains such as gemini.google.com, perplexity.ai, opera.com, or claude.ai. This configuration is indicative of potential AI agent hijacking, allowing unauthorized code execution and traffic interception on trusted vendor websites.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
004
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
19 days ago
001
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
404
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
19 days ago
101
Page 225 of 1871