Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects unauthorized access to the Directory Replication Service (DRS) using Event ID 4662. The rule looks for access requests to sensitive Active Directory replication objects (GUIDs 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 and 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) initiated by accounts other than Domain Controller machine accounts, which is a signature behavior of tools like Mimikatz lsadump::dcsync or Impacket's secretsdump.py.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin) or PowerShell cmdlets to delete Volume Shadow Copies or backup catalogs. This behavior is commonly associated with ransomware attempts to prevent system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule monitors for persistence mechanisms by detecting modifications to Windows Registry Run/RunOnce keys or the creation of files within the Windows Startup folder. It specifically flags instances where the executable or script being registered resides in high-risk directories such as Temp, AppData, or Downloads, and correlates these events with recent process execution to confirm the persistence activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects potential Windows token manipulation by correlating logon events containing sensitive privileges (SeDebugPrivilege/SeImpersonatePrivilege) with subsequent process creation events under a different user context within a short timeframe. It further validates the activity by incorporating Sysmon Event ID 10 alerts that identify process access patterns commonly associated with token duplication or impersonation techniques used in post-exploitation frameworks like Cobalt Strike.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the issuance or renewal of Kerberos Ticket-Granting Tickets (TGT) (Event IDs 4768 and 4769) where the ticket lifetime or renewal duration exceeds standard Windows domain Kerberos policy defaults (typically 10 hours for lifetime and 7 days for renewal). Deviations from these standard thresholds are common indicators of forged Golden Tickets created using an exfiltrated KRBTGT hash.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of the rclone utility (including renamed binaries) using command-line arguments consistent with data exfiltration or synchronization (copy, sync, move) that is followed by network communication to known cloud storage providers commonly abused for staging and exfiltration in ransomware attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects active attempts to disable or interfere with security products, including EDR agents and antivirus software. The rule monitors for the use of 'sc.exe' to stop or reconfigure services, 'taskkill' to terminate security-related processes, and PowerShell commands utilizing 'Set-MpPreference' to modify Windows Defender real-time protection settings. These actions are frequently observed as a precursor to ransomware deployment or other malicious activities designed to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects potential lateral movement by monitoring user accounts performing interactive RDP logons (LogonType 10) to multiple distinct internal hosts within a 15-minute window. Additionally, identifies RDP logons occurring outside of standard business hours (before 6 AM or after 8 PM), a pattern often associated with human-operated ransomware activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects potential ransomware activity by correlating the execution of native Windows utilities used to inhibit system recovery (vssadmin, wmic, wbadmin, bcdedit) followed by a high volume of file modification events on the same host within a 15-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects two distinct methods of living-off-the-land proxy execution: first, MSBuild.exe spawning network connections after executing inline tasks defined in XML project files; second, Regsvr32.exe performing 'Squiblydoo' execution by loading COM scriptlets from remote URLs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects command-line execution patterns indicative of Anti-Malware Scan Interface (AMSI) bypass attempts. The rule looks for attempts to manipulate internal .NET AmsiUtils fields, modify AmsiScanBuffer, or utilize VirtualProtect against amsi.dll memory regions, all of which are common techniques employed by malicious loaders to evade script-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects Kerberos service ticket requests (Event ID 4769) that utilize weak RC4 encryption (0x17). This behavior is characteristic of Kerberoasting, where attackers request service tickets for service accounts in order to perform offline brute-force attacks to recover the service account password. The rule filters out machine account requests and focuses on standard user or service account requests.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects suspicious PowerShell execution patterns involving encoded commands, hidden window styles, or common download cradles combined with code obfuscation techniques. This rule monitors PowerShell ScriptBlock Logging (Event ID 4104) for combinations of indicators often used by threat actors to evade detection, such as Base64-encoded strings, hidden execution flags, network download utilities, and script obfuscation techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects Kerberos service ticket requests (Event ID 4769) that utilize weak RC4 encryption (0x17). This behavior is characteristic of Kerberoasting, where attackers request service tickets for service accounts in order to perform offline brute-force attacks to recover the service account password. The rule filters out machine account requests and focuses on standard user or service account requests.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to delete volume shadow copies, backup catalogs, or disable recovery mechanisms. This behavior is commonly associated with ransomware or destructive attacks attempting to inhibit system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects attempts to perform a DCSync attack by monitoring for Windows Event ID 4662 (Object Access) with specific Directory Replication Service (DRS) GUIDs. These GUIDs are used by attackers to request the replication of sensitive data, such as password hashes, from a Domain Controller without having direct access to it. This technique is commonly used by tools like Mimikatz and Impacket's secretsdump to extract credentials from Active Directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects the creation of named pipes with names that match default or commonly customized patterns used by Cobalt Strike Beacons for inter-process communication (IPC) and lateral movement. The detection specifically targets common pipe naming conventions such as those starting with 'msagent_', 'MSSE-', 'postex_', 'status_', and 'mypipe-', which are frequently observed in Cobalt Strike configurations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects common LSASS memory dumping techniques, including suspicious process access rights (EventID 10) and the execution of tools or techniques (EventID 1) such as comsvcs.dll, procdump, taskmgr, or werfault, which are often used to harvest credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the creation of new system services using EventID 7045 where the ImagePath points to suspicious temporary directories, administrative shares (ADMIN$), or utilizes randomly generated service names. This pattern is commonly associated with PsExec-style lateral movement and ransomware staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects modifications to Windows Registry persistence keys (Run, RunOnce, RunServices, RunServicesOnce) where the referenced executable or script path resides in low-trust locations such as AppData, Temp, or Public directories. This pattern is commonly used by adversaries to establish persistence after initial execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects suspicious cross-process access patterns targeting trusted system processes (svchost.exe, explorer.exe, notepad.exe) by utilizing broad process access rights (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD). This behavior is characteristic of process injection techniques like process hollowing, often employed by loaders and malware to execute code within the context of a legitimate process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Page 228 of 1871