Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects common SQL injection patterns (such as UNION SELECT, tautologies, sleep functions, and information_schema queries) within HTTP URI parameters and HTTP POST request bodies, which are indicative of an attempt to manipulate backend database queries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects HTTP POST requests with 'photo' in the URI and Gzip-compressed body content, which is a known C2 communication pattern used by the IcedID banking trojan.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects high-volume SSH authentication attempts originating from a single source IP targeting a server on port 22, indicating a potential brute force attack.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects HTTP POST requests characteristic of TrickBot C2 beaconing. The rule identifies specific URI structures, Content-Type headers set to 'application/octet-stream', and unique request body behaviors that are indicative of TrickBot communication patterns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects HTTP traffic patterns characteristic of Qakbot (QBot) malware command-and-control (C2) communication. This rule monitors for POST requests to .php files featuring a specific hardcoded User-Agent (IE 7.0 on Windows NT 5.1), a 'Cookie' header, 'application/octet-stream' content type, and a request body length of at least 201 characters.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
004
Detects HTTP traffic patterns associated with the default staging URIs of the PowerShell Empire C2 framework. This rule identifies inbound requests to specific .php files (admin/get, news, login/process) with a 'session=' cookie, which are characteristic of Empire agent beaconing behavior.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
This rule monitors for known string patterns associated with the initialization and command execution of the Metasploit Meterpreter reverse TCP payload. By inspecting network traffic for characteristic C2 handshake and command strings, it identifies active Meterpreter sessions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects DNS tunneling attempts by identifying DNS queries with abnormally long subdomains (greater than 50 characters) that exhibit a high request rate (20 or more queries within 60 seconds). This behavior is characteristic of C2 communication tools such as iodine or dnscat2, which encode data within DNS query labels to bypass traditional network security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects sequential suspicious SMB activity characteristic of PsExec lateral movement: connection to ADMIN$ or C$ administrative shares, followed by the upload of an executable or batch file to the share, and subsequently the usage of SVCCTL (CreateServiceW/StartServiceW) to execute the uploaded binary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects a suspicious volume of cloud resource deletions occurring within a short 15-minute window, specifically targeting multiple storage accounts and SQL database/server instances. This behavior is indicative of a malicious actor or an automated script attempting to disrupt business operations or destroy data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects instances where a user account registers a new Multi-Factor Authentication (MFA) method (such as TOTP or Authenticator app) shortly (within 30 minutes) after a high-risk or potentially anomalous sign-in event. This pattern is commonly associated with adversary-in-the-middle (AiTM) phishing attacks where an attacker captures an authenticated session and uses it to enroll a secondary, attacker-controlled MFA device for persistent account access.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
003
The following analytic identifies when an O365 email recipient receives and then deletes emails related to password or banking/payroll changes within a short period.
This behavior may indicate a compromised account where the threat actor is attempting to redirect the victims payroll to an attacker controlled bank account.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
7 days ago
000
The following analytic identifies when an O365 email account sends an excessive number of email attachments to external recipients within a short period (within 1 hour).
This behavior may indicate a compromised account where the threat actor is attempting to exfiltrate data from the mailbox.
Threat actors may attempt to transfer data through email as a simple means of exfiltration from the compromised mailbox.
Some account owner legitimate behaviors can trigger this alert, however these actions may not be aligned with organizational expectations / best practice behaviors.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
7 days ago
000
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
101
Detects an Active Directory Certificate Services (AD CS) Certificate Enrollment Service (CES) SOAP request that includes a 'CertificateTemplate' item in the 'AdditionalContext' body, potentially indicating a directed attempt to request a specific certificate template during enrollment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
This rule detects potential NTLM relay or authentication downgrade attempts by monitoring HTTP POST requests to the Certificate Enrollment Service (CES) endpoint. It specifically flags when an 'Authorization' header contains an NTLM-wrapped 'Negotiate' token, which is often indicative of an attacker attempting to coerce or relay authentication material to the service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
The following analytic identifies instances where CrushFTP has blocked access due to exceeding the maximum number of simultaneous connections from a single IP address. This activity may indicate brute force attempts, credential stuffing, or automated attacks against the CrushFTP server. This detection is particularly relevant following the discovery of CVE-2025-31161, an authentication bypass vulnerability in CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
005
The following analytic detects Log4Shell JNDI payload injections via outbound connections. It identifies suspicious LDAP lookup functions in web logs, such as `${jndi:ldap://PAYLOAD_INJECTED}`, and correlates them with network traffic to known malicious IP addresses. This detection leverages the Web and Network_Traffic data models in Splunk. Monitoring this activity is crucial as it targets vulnerabilities in Java web applications using log4j, potentially leading to remote code execution. If confirmed malicious, attackers could gain unauthorized access, execute arbitrary code, and compromise sensitive data within the affected environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
005
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
003
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
avatar
Arnold Chan@slaz
avatar
SlimKQL
13 days ago
003