Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
KQL Query from file: Network detection - C2 domains and static key
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
KQL Query from file: Network detection - C2 domains and static key
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
This rule detects the presence of the malicious 'pdf-para-texto@extensao.local' Firefox extension on disk. This extension is known to perform browser-based credential interception by patching the WebAuthn PublicKeyCredential interface at document_start on Google-related domains to facilitate account takeover.
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
Detects a multi-stage infection chain involving communication with known malicious infrastructure ('mnoskemp.beer'), staging and extraction of password-protected archives using '7za.exe' in temporary directories, installation of a spoofed OBS Studio MSI package, and subsequent DLL side-loading of malicious libraries (e.g., 'obs.dll', 'WSql-2.dll') by the 'obs64.exe' process when initiated from outside legitimate installation paths.
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
000
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
avatar
Ankit Mehta@Secvyn
Defender - KQL
16 days ago
000
Detects the use of the 'Add-MpPreference' PowerShell cmdlet with the '-ExclusionPath' parameter, which is used to add file, folder, or extension exclusions to Microsoft Defender. Attackers frequently use this technique to prevent security software from scanning or detecting malicious files or directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the execution of PowerShell with encoded commands originating from scripting engines wscript.exe or cscript.exe. The command line contains indicators of malicious activity such as references to external domains, archive expansion, or specific executable payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the execution of a process named 'msedge.exe' from the 'ProgramData\Microsoft\Windows\Telemetry' directory. Legitimate Microsoft Edge executables do not run from this location, suggesting an attempt to masquerade as the legitimate browser to bypass security controls or evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule identifies the execution or presence of files matching a known list of MD5 hashes associated with malicious activity. By monitoring file metadata, this rule flags instances where specific identified threat files are present on the system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects processes flagged by SentinelOne's behavioral engine with an 'Evasion' indicator. Specifically, this captures behaviors where a process performs manual module or function export enumeration (such as traversing the PEB Ldr linked list or parsing the EAT) to resolve API addresses, a technique often used to avoid standard dynamic-resolution APIs like LoadLibrary or GetProcAddress in order to bypass EDR API hooking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects unauthorized or suspicious processes (like Python scripts or random executables) accessing Telegram Desktop's local 'tdata' directory, which contains user session information, and simultaneously exhibiting network activity directed towards Telegram API domains. This behavior is highly indicative of infostealer activity, where a malicious process attempts to harvest local Telegram session data for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects modifications to Microsoft Defender antivirus exclusions. Adversaries often add paths or files to the exclusion list to prevent the detection of malicious tools or staging folders during cyberattacks. The rule monitors both command-line execution of PowerShell (Add-MpPreference/Set-MpPreference) and direct registry modifications related to Windows Defender paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the HEAVYGRAM second-stage implants 'RuntimeSSH.exe' or 'winappx.exe' establishing persistence by adding entries to Windows Registry Run or RunOnce keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Page 231 of 1871