Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where AI-assisted development tools (such as Claude, Codex, Copilot, or Gemini) initiate command-line processes (e.g., shells, interpreters, or network utilities) with arguments indicative of credential access, reconnaissance, or sensitive file interactions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
003
Detects the execution of destructive SQL commands (e.g., DROP, TRUNCATE, mass DELETE) via common command-line database clients. These patterns are often observed when threat actors attempt to destroy forensic evidence or interrupt database availability immediately following unauthorized data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects web or application server processes (Apache, Nginx, IIS, Tomcat, PHP) spawning command interpreters or scripting engines. This behavior is indicative of a post-exploitation activity where an attacker executes commands following a remote code execution exploit against the web application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects malicious JavaScript injection on e-commerce checkout or payment pages designed to harvest sensitive payment card information (PAN, CVV, expiry) and exfiltrate the stolen data to an external endpoint. This behavior is indicative of a digital credit card skimmer (e.g., Magecart style) deployed following a compromise of the web application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects Terraform CLI activity interacting with suspicious domains or modules, specifically targeting known repositories or namespaces (e.g., gocommunity.io, gogets.dev). It monitors for Terraform initialization or application patterns referencing these domains in process command lines, as well as the creation of Terraform provider files within these specific namespaces. This behavior is indicative of potential supply chain compromise involving malicious Terraform modules or dependencies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects when common web server processes or service accounts spawn unexpected interpreter, shell, or reconnaissance tools, which is a common indicator of post-exploitation activity following a successful Remote Code Execution (RCE) attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects execution of a specific suspicious executable file masquerading in the Windows Temp directory, coupled with the access of an associated .ini configuration file. This behavior is indicative of AsyncRAT deployment, often involving initial execution or staging of configuration files within volatile user directories.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
25 days ago
107
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that involve indicators often associated with malicious behavior, such as targeting temporary or publicly writable directories ('appdata', 'temp', 'programdata') or employing suspicious command-line flags (e.g., encoded commands, highest privileges, or execution on system startup).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects Kerberoasting activity by identifying a high volume of RC4-encrypted (0x17) Kerberos Service Ticket (TGS) requests from a single user account against multiple distinct service principal names (SPNs) within a short timeframe. This behavior is highly indicative of automated credential harvesting tools such as Rubeus or Impacket.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects potential Pass-the-Hash lateral movement by identifying NTLM network logons (Event ID 4624, LogonType 3) on a host that lack a preceding interactive (LogonType 2, 10) or Kerberos-authenticated logon, coupled with subsequent access to sensitive administrative shares (Event ID 5140) by the same user account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI). This rule monitors for command-line arguments indicative of reflection-based patching of AmsiUtils and forced AmsiScanBuffer failures, as well as registry modifications to AMSI providers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the creation of new Windows services using sc.exe or PowerShell where the binary path is located in common user-writable or temporary directories (e.g., Temp, AppData, ProgramData), or where the service name mimics legitimate Windows system services, a technique often used for persistence or lateral movement (e.g., PsExec).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects modifications to Windows Registry run keys and startup folder locations that are commonly used for persistence. It specifically flags when entries point to scripts, interpreted binaries, or files located in directories often used by attackers to hide malicious payloads (e.g., AppData, Temp, ProgramData).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to delete volume shadow copies, backup catalogs, or disable system recovery features. The rule further correlates this activity with preceding mass file activity to identify potential ransomware or destructive attack behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of PowerShell with common obfuscation or download flags (e.g., -EncodedCommand, IEX, DownloadString) specifically when the parent process is a common attack vector entry point such as Office applications, web browsers, or script hosts (wscript/cscript/mshta). This behavior is characteristic of phishing-based execution chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects anomalous Kerberos TGS (Ticket Granting Service) requests using weak RC4-HMAC (0x17) encryption. The rule looks for accounts requesting multiple service tickets for distinct Service Principal Names (SPNs) within a short time window, which is a common behavior pattern for tools like Rubeus or GetUserSPNs.py during the credential-harvesting phase of a Kerberoasting attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects potential AS-REP Roasting activity by monitoring Windows Event ID 4768 (TGT Request). It identifies multiple Kerberos AS-REQ requests from a single IP address within a 10-minute window, where the PreAuthType is 0 (indicating no pre-authentication) and the encryption type is RC4 (0x17 or 23). This behavior is characteristic of enumeration and exploitation tools such as Rubeus or Impacket's GetNPUsers.py, which attempt to obtain extractable TGTs for accounts that do not require Kerberos pre-authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects anomalous NTLM network logons (Logon Type 3) where the same user account authenticates to multiple distinct hosts within a short time window. This behavior is correlated with NTLM validation (4776) events to identify potential Pass-the-Hash activity used for lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the creation of scheduled tasks using schtasks.exe or Event ID 4698 that involve suspicious binaries (e.g., powershell, mshta), execution from user-writable directories, or tasks configured to run with SYSTEM privileges, which are common indicators of persistence establishment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects anomalous Kerberos ticket requests characteristic of Golden Ticket attacks. These forged tickets are created offline using the KRBTGT account hash, bypassing legitimate KDC TGT issuance, and frequently exhibit default Mimikatz artifacts such as RC4 encryption or extended ticket lifetimes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects the creation of new Windows services (Event IDs 7045 and 4697) where the service binary path points to potentially suspicious locations such as user profiles, temp directories, program data, or common command interpreters. This pattern is frequently used by adversaries for persistence mechanisms or to deploy malicious drivers/tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Page 227 of 1871