Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
203
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
005
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
005
This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
205
IOC sweep against network telemetry for confirmed BengalSEO/MayaBot campaign infrastructure: the Hostmaza backend IP (5.101.140.80), Matomo tracking domains (stats.us3.org, us3.my), named MayaBot C2 domains (cus.cam, dll.lat, us99.org), and the ~170-domain Traffic Distribution System redirector fleet used to funnel victims to payload delivery. The source intel report contains no file hashes (MD5/SHA1/SHA256) -- only IPs, domains, and URLs -- so this sweep is IP/domain-only. Note the much larger corpus of single-use lure-page domains (~1,000 additional indicators) is excluded as too high-churn for static embedding.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
003
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
Detects high-volume file download, access, or preview activity originating from known anonymous proxy services. This behavior is indicative of potential data exfiltration or unauthorized mass data collection from cloud storage applications.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
19 days ago
6015
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
205
Detects high-frequency requests directed at common model-serving API endpoints, which may indicate an attacker attempting to perform model extraction or model inversion attacks by repeatedly querying the model to infer its parameters or training data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
100
Detects malicious shell commands or scripts (e.g., bash, powershell, curl, wget) embedded within HTTP POST request bodies that appear to be AI agent tool-call payloads. This activity is indicative of prompt injection or AI tool-use exploitation attempts designed to execute arbitrary code on the underlying host or container.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
100
This rule detects potential automated subdomain enumeration by monitoring for a high volume of DNS queries (200 or more within 60 seconds) originating from a single host. Such behavior is characteristic of reconnaissance activities used to discover subdomains and map out network infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
100
This rule detects high-frequency HTTP 401 Unauthorized responses directed at API endpoints (specifically matching '/v1/') within a short window, which is indicative of an adversary attempting to brute-force or credential-stuff API keys.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
100
Detects instances where a user grants high-privilege permissions (Mail.Read, Files.ReadWrite.All, offline_access) to an OAuth application within 24 hours of a risky sign-in event. This pattern is commonly observed in AiTM (Adversary-in-the-Middle) or consent-phishing attacks designed to establish persistent access to cloud resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects potential Adversary-in-the-Middle (AiTM) MFA bypass attacks (quishing). The rule correlates receipt of an email containing an image attachment (potential QR code) but no URL, followed by a risky mobile sign-in event from a device that is unmanaged or lacks trust within a two-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects potential Adversary-in-the-Middle (AiTM) activity by identifying successful multi-factor authenticated sign-in events from the same user across different geographic regions and IP addresses within a one-hour timeframe, which is characteristic of session cookie replay attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects a sequence of events where a user with a high-risk or compromised sign-in status registers a new device in Entra ID shortly after the event, followed by subsequent sign-ins from that device that bypass multi-factor authentication (MFA) via Conditional Access policies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
004
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
004
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
104
Detects inbound emails containing malicious QR codes (quishing) or HTML smuggling payloads designed to facilitate credential harvesting (AiTM). The rule identifies suspicious attachments, HTML-based obfuscation (e.g., atob, Blob) in email bodies, and QR-code-themed image attachments, filtering out internal communications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
This rule detects activities indicative of an attacker attempting to establish an adversary-in-the-middle (AiTM) position within an on-premises network. It flags potential NTLM relay attempts (via loopback or invalid workstation indicators) and unauthorized name resolution spoofing (LLMNR/NBT-NS) used to intercept and relay authentication traffic for MFA bypass or credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002