Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects a single user account performing NTLM network logons (LogonType 3) to 3 or more distinct hosts within a short time period. This pattern is commonly associated with lateral movement techniques such as Pass-the-Hash, where an attacker uses compromised credentials to spread across a network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects access to sensitive Active Directory objects, such as the Domain Admins group or other privileged accounts, as identified by specific GUIDs in Windows Event ID 4662. This event is generated when an object in Active Directory is accessed, and monitoring these specific GUIDs can indicate an adversary attempting to perform reconnaissance or modify sensitive directory objects.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of rundll32.exe or regsvr32.exe to execute code via remote scripts, COM scriptlets, or JavaScript. This technique is often used in fileless malware or to bypass execution policies by loading scripts directly from a URL or local file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to inhibit system recovery by deleting shadow copies, backup catalogs, or disabling automatic recovery features. This behavior is commonly observed in ransomware attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects attempts to impair or disable security defenses on Windows systems. It specifically monitors for three categories of malicious behavior: PowerShell-based AMSI (Antimalware Scan Interface) bypass techniques, commands to stop security-related services (e.g., Windows Defender, SentinelOne, CrowdStrike Falcon), and the use of 'reg' or 'PowerShell' to modify registry keys associated with disabling antivirus or real-time monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects instances where a signed executable loads an unsigned, invalid, or revoked DLL that shares the same base filename, located outside of standard Windows system directories (System32, SysWOW64, WinSxS). This behavior is characteristic of DLL search-order hijacking and side-loading attacks often employed by loaders and malware such as Cobalt Strike.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects Active Directory Certificate Services (AD CS) certificate requests that include a Subject Alternative Name (SAN) or custom altname attribute, specifically those enabling client authentication. This pattern is commonly associated with the ESC1 privilege escalation technique, where an adversary requests a certificate that impersonates another user or machine account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects Kerberos TGT and service ticket requests that utilize deprecated or weak encryption types (RC4/DES) often associated with Golden Ticket attacks, specifically in environments where AES is mandated. The rule groups these events by user, service, and IP address to identify potential anomalies indicative of credential forgery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
19 days ago
001
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
19 days ago
201
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
001
The following analytic detects process injection into Notepad.exe using Sysmon EventCode 10. It identifies suspicious GrantedAccess requests (0x40 and 0x1fffff) to Notepad.exe, excluding common system paths like System32, Syswow64, and Program Files. This behavior is often associated with the SliverC2 framework by BishopFox. Monitoring this activity is crucial as it may indicate an initial payload attempting to execute malicious code within Notepad.exe. If confirmed malicious, this could allow attackers to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
The following analytic detects attempts to read LSASS memory, indicative of credential dumping.
It leverages Sysmon EventCode 10 and checks for "PROCESS_VM_READ" with query information access on lsass.exe.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
The following analytic detects an uncommon process requesting full access rights to winlogon.exe, which may indicate Rubeus exporting Kerberos tickets from memory.
It leverages Sysmon EventCode 10 and checks for full-access rights, specifically the value 0x1f3fff.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
101
The following analytic detects duplicate-handle and query-limited-information access to winlogon.exe from an uncommon or public source path.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
101
The following analytic detects possible credential dumping by identifying suspicious process access to LSASS with credential-dumping-related call traces.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_LIMITED_INFORMATION (0x1000) and PROCESS_DUP_HANDLE (0x40).
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
101
The following analytic detects a process requesting PROCESS_TERMINATE access to Lsass.exe.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_TERMINATE (0x1).
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
The following analytic detects WMI token impersonation by identifying `wmiprvse.exe` requesting the query, VM, and duplicate-handle rights associated with WMI process access.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_INFORMATION (0x400), PROCESS_QUERY_LIMITED_INFORMATION (0x1000), PROCESS_VM_OPERATION (0x8), PROCESS_VM_READ (0x10), PROCESS_VM_WRITE (0x20), PROCESS_DUP_HANDLE (0x40), and PROCESS_ALL_ACCESS (0x1f3fff).
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
The following analytic detects email files (.pst or .ost) being created outside the standard Outlook directories.
It leverages the Endpoint.Filesystem data model to identify file creation events and filters for email files not located in "C:\Users\*\My Documents\Outlook Files\*" or "C:\Users\*\AppData\Local\Microsoft\Outlook*".
This activity is significant as it may indicate data exfiltration or unauthorized access to email data.
If confirmed malicious, an attacker could potentially access sensitive email content, leading to data breaches or further exploitation within the network.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
The following analytic detects the creation of an lsass.exe process dump using Windows Task Manager.
It leverages Sysmon EventID 11 to identify file creation events where the target filename matches *lsass*.dmp.
This activity is significant because creating an lsass dump can be a precursor to credential theft, as the dump file contains sensitive information such as user passwords.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
101
The following analytic detects unauthorized access to Outlook credentials stored in the Windows registry.
It leverages Windows Security Event logs, specifically EventCode 4663, to identify access attempts to registry paths associated with Outlook profiles.
This activity is significant as it may indicate attempts to steal sensitive email credentials, which could lead to unauthorized access to email accounts.
If confirmed malicious, this could allow attackers to exfiltrate sensitive information, impersonate users, or execute further unauthorized actions within Outlook, posing a significant security risk.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
19 days ago
001
Page 229 of 1871