Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

KQL Query from file: ClickFix – Suspicious Persistence Scheduled Task
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
KQL Query from file: ClickFix – Suspicious User Run Key Persistence
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
KQL Query from file: ClickFix – PowerShell Launching MSI from Temp
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
003
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects two suspicious Kerberos activity patterns indicative of potential credential theft or reconnaissance: 1) A single account requesting tickets for multiple services or across multiple hosts in a short duration, which may indicate automated credential harvesting such as Kerberoasting; 2) The use of RC4 encryption (0x17) for Kerberos tickets, which is an older, weaker protocol and may indicate a forced downgrade attack to facilitate offline password cracking.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
21 days ago
2033
This rule detects the creation of potentially malicious script or executable files (.bat, .ps1, .exe, .vbs) within the Windows Startup folder. It triggers when these files are created by processes typically used for automation or development (dotnet, python) or processes utilizing specific semantic/download-related command lines. The rule further correlates this activity with the presence of PowerShell commands indicative of script downloading or code execution (e.g., IEX, DownloadString) by the same device within the same timeframe, suggesting persistent execution of potentially malicious code.
avatar
Ishaan S@isrv
avatar
Hunters
13 days ago
003
Detects the execution of pypykatz or Python scripts invoking pypykatz commands to perform credential dumping, specifically targeting LSASS memory or minidump files.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
001
Detects a process initiating a memory dump of lsass.exe (using --dump arguments) followed within 15 minutes by the creation of a hexadecimal-named .tmp file in the Windows\Temp directory. This behavioral pattern is characteristic of credential dumping using reflected cloning or similar techniques, followed by the staging of obfuscated or encrypted minidump data for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
001
This rule detects LSASS credential dumping attempts by correlating the execution of a dump command (via process command line) with the subsequent creation of a temporary file in the Windows Temp directory. The rule is specifically designed to bypass evasion techniques that introduce randomized delays between the LSASS process access and the file write operation by utilizing a 30-minute join window.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
001
Detects the pidclone-style LSASS credential dumper that clones the target process into a suspended state, mirrors its memory, generates a minidump, and writes an XOR-encrypted copy of the dump to a randomized filename under Windows\Temp
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
001
Detects a sequence of events indicative of LSASS memory dumping where a process opens a handle to lsass.exe and subsequently creates a uniquely named temporary file (16-character hexadecimal filename) in the Windows Temp directory within a short timeframe. This behavior is often associated with the obfuscated flushing of a stolen memory dump to disk to evade signature-based detection.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
101
Detects the execution of pypykatz or Python scripts invoking pypykatz commands to perform credential dumping, specifically targeting LSASS memory or minidump files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects command-line activity indicative of attempts to dump LSASS memory after performing in-memory unhooking or bypassing of security monitoring DLLs (ntdll.dll, amsi.dll, win32kbase.sys). This behavior is characteristic of adversaries attempting to harvest credentials while evading EDR/AV visibility.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects a process initiating a memory dump of lsass.exe (using --dump arguments) followed within 15 minutes by the creation of a hexadecimal-named .tmp file in the Windows\Temp directory. This behavioral pattern is characteristic of credential dumping using reflected cloning or similar techniques, followed by the staging of obfuscated or encrypted minidump data for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
This rule detects LSASS credential dumping attempts by correlating the execution of a dump command (via process command line) with the subsequent creation of a temporary file in the Windows Temp directory. The rule is specifically designed to bypass evasion techniques that introduce randomized delays between the LSASS process access and the file write operation by utilizing a 30-minute join window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects outbound HTTP POST requests associated with the Telepuz modular loader. The rule monitors for specific URI patterns, request body parameters, and suspicious User-Agent strings indicative of PowerShell or MSHTA command-and-control communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
101