Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the use of rundll32.exe to execute comsvcs.dll's MiniDump functionality against the LSASS process, a common technique for dumping credentials. The rule includes behavioral correlation by identifying the same user account executing this pattern on multiple devices within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
103
Detects unauthenticated attempts to access Adobe Commerce/Magento REST API endpoints. This rule specifically looks for HTTP GET requests containing /rest/ and /V1/ paths without an Authorization header, which may indicate an attempt to exploit CVE-2026-71362.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects incoming HTTP POST requests to the Zimbra OnlyOffice document handler containing path traversal sequences (e.g., '..'). This pattern is indicative of an attempt to exploit CVE-2026-93643 by manipulating document save or callback paths to access unauthorized files on the server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects attempts to exploit a buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series switches. The rule monitors for oversized POST requests directed at CGI scripts on the device's web management interface.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
103
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
104
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
004
This rule detects HTTP POST requests to the Apache Qpid Broker-J Management API that include a pre-set JSESSIONID in the cookie header during a login operation, indicating an attempt to exploit CVE-2026-92609 via session fixation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects attempts to access administrative or configuration endpoints on Cisco Identity Services Engine (ISE) without providing valid authentication headers, cookies, or authorization tokens. This behavior is indicative of exploitation attempts targeting CVE-2026-20192 to gain unauthorized administrative access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
203
Detects attempts to disable Windows Defender by either executing known Defender Control utilities or by modifying registry keys associated with the disabling of anti-spyware features or the WinDefend service startup.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
505
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
205
Detects the clearing of Windows Security Event Logs (EventID 1102) within 15 minutes of a successful user logon (EventID 4624) on the same host. This activity is a common anti-forensics technique used by adversaries to hide malicious actions following an authenticated session.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
305
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
105
This rule detects attempts to exploit the Microsoft Support Diagnostic Tool (MSDT) vulnerability CVE-2022-30190, known as 'Follina'. The rules monitor for malicious HTTP traffic and payloads that leverage the 'ms-msdt' URI scheme to execute arbitrary commands, often delivered via weaponized documents or external references to remote malicious HTML files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects outbound network traffic exhibiting the default self-signed TLS certificate subject and issuer fields 'O=Cobalt Strike' combined with the known default JA3 fingerprint '72a589da586844d7f0818ce684948eea' associated with Cobalt Strike C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects DNS queries with abnormally long subdomains matching patterns frequently used by Cobalt Strike DNS Beacons for command-and-control communications. The rule identifies hexadecimal or base32 encoded strings within subdomains that exceed 40 characters in length and occur frequently within a short time window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects network traffic patterns characteristic of the EternalBlue (MS17-010) exploit targeting the SMBv1 protocol. Specifically, it monitors for a malformed SESSION_SETUP request containing an unusually large payload, which is indicative of an attempt to trigger a buffer overflow in the SMB service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects common SQL injection patterns (such as UNION SELECT, tautologies, sleep functions, and information_schema queries) within HTTP URI parameters and HTTP POST request bodies, which are indicative of an attempt to manipulate backend database queries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000