Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

The following analytic detects the execution of native .NET binaries from non-standard directories within the Windows operating system.
It leverages Endpoint Detection and Response (EDR) telemetry, comparing process names and original file names against a predefined lookup "is_net_windows_file".
This activity is significant because adversaries may move .NET binaries to unconventional paths to evade detection and execute malicious code.
If confirmed malicious, this behavior could allow attackers to execute arbitrary code, escalate privileges, or maintain persistence within the environment, posing a significant security risk.
Also this analytic leverages a sub-search to enhance performance. sub-searches have limitations on the amount of data they can return. Keep this in mind if you have an extensive list of ransomware note file names.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This Analytic detects the execution of a process attempting to access the hosts file.
The hosts file is a critical file for network configuration and DNS resolution.
If an attacker gains access to it, they can redirect traffic to malicious websites, serve fake content or block legitimate security websites.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies the use of protocol handlers executed via the command line. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry. This activity is significant because protocol handlers can be exploited to execute arbitrary commands or launch applications, potentially leading to unauthorized actions. If confirmed malicious, an attacker could use this technique to gain code execution, escalate privileges, or maintain persistence within the environment, posing a significant security risk.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the disabling of important audit policies. It leverages EventCode 4719 from Windows Security Event Logs to identify changes where success or failure auditing is removed. This activity is significant as it suggests an attacker may have gained access to the domain controller and is attempting to evade detection by tampering with audit policies. If confirmed malicious, this could lead to severe consequences, including data theft, privilege escalation, and full network compromise. Immediate investigation is required to determine the source and intent of the change.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects when DLLs with known abuse history are loaded from an unusual location.
This activity may represent an attacker performing a DLL search order or sideload hijacking technique.
These techniques are used to gain persistence as well as elevate privileges on the target system.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies a LOLBAS process being executed outside of it's expected location.
Processes being executed outside of expected locations may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies the execution of commonly used NirSoft utilities on Windows systems.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution details such as process name, parent process, and command-line arguments.
This activity is significant for a SOC because NirSoft utilities, while legitimate, can be used by adversaries for malicious purposes like credential theft or system reconnaissance.
If confirmed malicious, this activity could lead to unauthorized access, data exfiltration, or further system compromise.
Note that this search does not use a where clause to filter out known benign paths, as NirSoft utilities can be executed from various locations. This might hinder performance in environments with high data volumes.
Apply additional filtering as necessary to enhance this.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the execution of multiple offensive toolkits and commands through the process execution datamodel. This method captures commands given directly to powershell.exe, allowing for the identification of suspicious activities including several well-known tools used for credential theft, lateral movement, and persistence. If confirmed malicious, this could lead to unauthorized access, privilege escalation, and potential compromise of sensitive information within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the execution of multiple offensive toolkits and commands by leveraging PowerShell Script Block Logging (EventCode=4104). This method captures and logs the full command sent to PowerShell, allowing for the identification of suspicious activities including several well-known tools used for credential theft, lateral movement, and persistence. If confirmed malicious, this could lead to unauthorized access, privilege escalation, and potential compromise of sensitive information within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the creation or connection to named pipes used by potentially unwanted applications (PUAs) like VPNs or utilities like PsExec.
It leverages Sysmon EventCodes 17 and 18.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the creation or connection to known suspicious named pipes, which is a technique often used by offensive tools.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by RMM tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the creation of scheduled tasks designed to execute commands using native Windows shells like PowerShell, Cmd, Wscript, or Cscript or from public folders such as Users, Temp, or ProgramData. It leverages Windows Security EventCode 4698, 4700, and 4702 to identify when such tasks are registered, enabled, or modified. This activity is significant as it may indicate an attempt to establish persistence or execute malicious commands on a system. If confirmed malicious, this could allow an attacker to maintain access, execute arbitrary code, or escalate privileges, posing a severe threat to the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the creation, modification, or enabling of scheduled tasks with known suspicious or malicious task names. It leverages Windows Security EventCode 4698, 4700, and 4702 to identify when such tasks are registered, modified, or enabled. This activity is significant as it may indicate an attempt to establish persistence or execute malicious commands on a system. If confirmed malicious, this could allow an attacker to maintain access, execute arbitrary code, or escalate privileges, posing a severe threat to the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the creation of a Windows Service with a known suspicious or malicious name using Windows Event ID 7045. It leverages logs from the `wineventlog_system` to identify these services installations. This activity is significant as adversaries, including those deploying Clop ransomware, often create malicious services for lateral movement, remote code execution, persistence, and execution. If confirmed malicious, this could allow attackers to maintain persistence, execute arbitrary code, and potentially escalate privileges, posing a severe threat to the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the creation or connection to known suspicious C2 named pipes.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by C2 tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the creation or connection to known suspicious named pipes.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by malicious or suspicious tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain privilege escalation,
persistence, c2 communications, or further system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects the loading of known vulnerable Windows drivers, which may indicate potential persistence or privilege escalation attempts. It leverages Sysmon EventCode 6 to identify driver loading events and cross-references them with a list of vulnerable drivers. This activity is significant as attackers often exploit vulnerable drivers to gain elevated privileges or maintain persistence on a system. If confirmed malicious, this could allow attackers to execute arbitrary code with high privileges, leading to further system compromise and potential data exfiltration.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies DNS queries to domains associated with the 3CX supply chain attack. It leverages the Network_Resolution datamodel to detect these suspicious domain indicators. This activity is significant because it can indicate a potential compromise stemming from the 3CX supply chain attack, which is known for distributing malicious software through trusted updates. If confirmed malicious, this activity could allow attackers to establish a foothold in the network, exfiltrate sensitive data, or further propagate malware, leading to extensive damage and data breaches.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic identifies DNS queries from internal hosts to dynamic domain providers. It leverages DNS query logs from the `Network_Resolution` data model and cross-references them with a lookup file containing known dynamic DNS providers. This activity is significant because attackers often use dynamic DNS services to host malicious payloads or command-and-control servers, making it crucial for security teams to monitor. If confirmed malicious, this activity could allow attackers to bypass firewall blocks, evade detection, and maintain persistent access to the network.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The following analytic detects DNS queries to domains associated with known remote access software such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer. This detection is crucial as adversaries often use these tools to maintain access and control over compromised environments. Identifying such behavior is vital for a Security Operations Center (SOC) because unauthorized remote access can lead to data breaches, ransomware attacks, and other severe impacts if these threats are not mitigated promptly.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
Detects suspicious activity associated with Cobalt Strike Beacon communication, specifically monitoring for known default named pipes and specific user-agent strings commonly used by Cobalt Strike in HTTP/S traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Page 23 of 1866