Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects suspicious PowerShell command-line activity involving the use of encoded, obfuscated, or stealth-focused flags, as well as common patterns associated with fileless payload delivery and execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the creation of Windows scheduled tasks using schtasks.exe that exhibit high-risk indicators, such as targeting temporary or user-writable directories (Temp, AppData), setting high-privilege execution flags, or utilizing PowerShell with encoded payloads. These behaviors are commonly associated with the installation of persistence mechanisms by threat actors.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the creation of permanent WMI event subscriptions which can be used by adversaries to establish persistence by triggering malicious code execution upon specific system events. The rule monitors Sysmon events 19, 20, and 21 as well as Microsoft-Windows-WMI-Activity logs for modifications involving Event Filters, Consumers, and Bindings, specifically looking for CommandLineEventConsumer or ActiveScriptEventConsumer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the creation or modification of Windows Registry Run/RunOnce keys or files within the Startup folder where the target command path is deemed suspicious (e.g., temp directories, ProgramData), utilizes known LOLBins, or contains common obfuscation flags (e.g., -enc, IEX, -w hidden) frequently associated with persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the creation of new services consistent with PsExec or PAExec lateral movement. The rule monitors for Windows Event IDs 7045 and 4697 where the service name uses common PsExec/PAExec naming conventions or the image path points to suspicious locations such as admin shares or temporary directories often used by these tools for binary staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects Kerberos service ticket requests (TGS-REQ) using RC4 encryption (etype 0x17) and specific ticket options (0x40810000), which are commonly associated with Kerberoasting attacks. This rule filters out service accounts (ending in $) to reduce noise, as these legitimate account types frequently request tickets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the abuse of the Windows built-in utility 'certutil.exe' to download files or decode obfuscated payloads. Attackers frequently use certutil as a Living off the Land Binary (LOLBin) to bypass security controls by leveraging its native capabilities for file transfer (via URL cache) and base64 or hexadecimal decoding.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects a single account requesting an abnormally large number of Kerberos service tickets (Event ID 4769) using weak RC4 encryption (0x17) within a short window. This pattern is characteristic of Kerberoasting attacks, where an adversary requests service tickets for offline password cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of mshta.exe with suspicious command-line arguments that indicate the loading of remote HTML Applications (HTA) via URLs or inline scripts (javascript/vbscript). This behavior is often indicative of fileless malware execution and living-off-the-land techniques to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of PowerShell to download content from an external URL and immediately execute it in memory using common download cradles (e.g., Net.WebClient, IWR) combined with execution commands like IEX (Invoke-Expression). This is a common pattern for fileless malware delivery and post-exploitation activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects attempts to disable Windows Defender features via PowerShell, terminate critical security services using administrative tools like sc.exe or net.exe, or inject/patch AMSI (Antimalware Scan Interface) within a process context to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the creation or abuse of Volume Shadow Copies specifically to access the NTDS.dit file or the SYSTEM registry hive, a common technique for offline Active Directory credential dumping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects instances where common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) spawn child processes that are typically associated with command interpretation, scripting, or LOLBins (Living Off the Land Binaries). This behavior is often indicative of malicious macro execution, exploit payloads, or obfuscated command execution originating from malicious documents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects potential Pass-the-Hash (PtH) activity by monitoring Windows Security Event ID 4624 (Logon). The rule specifically targets logon type 9 (NewCredentials) combined with specific process/package names indicative of tools like Mimikatz, or anomalous NTLM network logons (logon type 3) that are not anonymous.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects instances where AI-assisted development tools (Claude, Codex, Copilot, Gemini) are used to execute git checkout commands. The rule filters for non-interactive parent processes to identify potentially automated or background execution of git operations by these development assistants.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
22 days ago
303
Detects instances where AI-assisted development tools (Claude, Codex, Copilot, Gemini) are used to execute git checkout commands. The rule filters for non-interactive parent processes to identify potentially automated or background execution of git operations by these development assistants.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
22 days ago
003
Detects instances where AI-assisted development tools (such as Claude, Codex, Copilot, or Gemini) initiate command-line processes (e.g., shells, interpreters, or network utilities) with arguments indicative of credential access, reconnaissance, or sensitive file interactions.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
22 days ago
003
Detects the creation or abuse of Volume Shadow Copies specifically to access the NTDS.dit file or the SYSTEM registry hive, a common technique for offline Active Directory credential dumping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects instances where common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) spawn child processes that are typically associated with command interpretation, scripting, or LOLBins (Living Off the Land Binaries). This behavior is often indicative of malicious macro execution, exploit payloads, or obfuscated command execution originating from malicious documents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects potential Pass-the-Hash (PtH) activity by monitoring Windows Security Event ID 4624 (Logon). The rule specifically targets logon type 9 (NewCredentials) combined with specific process/package names indicative of tools like Mimikatz, or anomalous NTLM network logons (logon type 3) that are not anonymous.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects processes opening lsass.exe with high-risk access rights consistent with credential dumping (Sysmon EventID 10), including known dumping tool patterns such as procdump or rundll32 invoking the comsvcs.dll MiniDump export.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Page 226 of 1871