Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects a suspected exploitation attempt of CVE-2024-21412. The rule identifies a chain of execution involving an internet shortcut (.url) masquerading as a common file type (e.g., .jpg.url), which subsequently opens another shortcut to a WebDAV/IP host. This sequence is used to bypass Mark-of-the-Web (MotW) protections and execute a malicious batch script and Rundll32 process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
3014
Detects the invocation of powershell.exe or pwsh.exe using encoded command flags (-EncodedCommand/-enc) in combination with stealth-oriented arguments such as -WindowStyle Hidden or -NoProfile. This pattern is frequently utilized by threat actors to execute obfuscated, malicious scripts while bypassing command-line visibility and standard profile configurations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Detects Active Directory DCSync replication requests by monitoring for Event ID 4662 associated with DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights. The rule triggers when these rights are requested by an entity (subject) originating from a host that is not recognized as a Domain Controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
202
This rule identifies suspicious Kerberos activity indicative of Golden or Silver Ticket attacks. It monitors for service ticket (4769) requests that occur without a preceding TGT request (4768) within a specified window, detects RC4 encryption downgrades on Kerberos requests in environments expected to use AES, and identifies tickets containing non-standard TicketOptions commonly associated with automated forgery tools like Mimikatz.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
Detects anomalous lateral movement behavior characterized by an account performing multiple NTLM authentication events (Logon Type 3) across distinct hosts within a short time window, specifically where Kerberos pre-authentication is absent. This pattern is frequently observed in Pass-the-Hash (PtH) attacks where attackers utilize stolen NTLM hashes to move laterally.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Detects anomalous lateral movement via Remote Desktop Protocol (RDP) by identifying three high-risk patterns: rapid RDP fan-out to multiple destination hosts from a single account, RDP access to sensitive servers from unauthorized source hosts, and RDP sessions followed by the execution of known post-exploitation or credential-theft tooling on the destination host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
This rule detects HTTP GET requests initiated by the Windows PowerShell User-Agent where the destination host is a decimal-encoded IP address. This pattern is commonly associated with ClickFix-style social engineering attacks, where users are tricked into executing obfuscated PowerShell commands to download malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects a process reading credential store files (Login Data) from multiple Chromium-based browsers, immediately followed by an HTTP POST request to a specific exfiltration endpoint associated with the Psychedelic Stealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects the creation of a Windows scheduled task named 'psychedelicloveUtils' using schtasks.exe, which is indicative of persistence mechanisms employed by the Psychedelic Stealer malware following installation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects unauthorized processes attempting to read sensitive wallet extension storage files or desktop application wallet data folders, a behavior characteristic of the Psychedelic Stealer malware designed to harvest cryptocurrency credentials prior to exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects the execution of msiexec.exe where the process image is located in the user's local AppData directory under specific suspicious folder names. This behavior is indicative of a user-land installer or potential malware attempting to maintain persistence or execute malicious packages while masquerading as common applications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
203
Detects attempts to terminate common antivirus and security software processes using 'taskkill.exe' with force flags. The rule specifically correlates this behavior with SQL Server processes (initiating or present on the host), suggesting an attempt to disable security controls to facilitate unauthorized activity or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects the loading of known DLLs (WinSparkle.dll, libcurl.dll, vim64.dll, dbghelp.dll, jli.dll, nvml.dll) from suspicious or non-standard file paths. The rule cross-references these image loads with file activity, identifying potential side-loading scenarios where a library is loaded from an unexpected directory or within an archive-related context. It also includes an explicit hash-based detection for a known malicious file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects a behavioral pattern associated with the NeedyMantis first-stage loader, which involves the loading of specific suspicious DLLs (masquerading as common software components) followed by the extraction or creation of an 'encryptbase64.ps1' second-stage loader within a short timeframe (10 minutes) on the same host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects host enumeration activities (listing processes, user information, and directory contents) performed by known legitimate binaries (e.g., poedit.exe, curl.exe, vim.exe) shortly after they have executed a suspicious sideloading event. This pattern is characteristic of the NeedyMantis actor performing initial discovery before C2 beaconing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects specific malicious archive payloads associated with NeedyMantis that contain a second-stage loader and spoofed system DLLs (e.g., dnsapi.dll, ws2_32.dll, msvcrt140.dll). These archives utilize XOR encoding or RtlDecompressBuffer packing and are designed for DLL sideloading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
003
Detects the use of the built-in Windows utility rundll32.exe to execute the MiniDump functionality within comsvcs.dll against the Local Security Authority Subsystem Service (LSASS). This technique is a common method for attackers to bypass signature-based security tools and obtain sensitive credentials from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
Detects the execution of PowerShell with suspicious flags such as encoded commands (-enc, -ec, -encodedcommand) combined with execution policy bypass flags and common .NET classes or methods used for downloading content from the internet (e.g., Net.WebClient, IEX, Invoke-WebRequest). This pattern is commonly observed in fileless malware delivery or secondary payload retrieval stages.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Detects the use of cloud synchronization utilities such as rclone (including renamed binaries) or Mega command-line tools to interact with cloud storage services. The rule correlates this execution with preceding mass file enumeration or access activity on the same host, which is a common pattern in ransomware double-extortion scenarios.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
202
Detects modifications to Windows Registry keys associated with persistence techniques, including LSA authentication package registration, custom credential provider registration, and manipulation of SafeBoot registry keys.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
102
This rule detects potential unauthorized Remote Monitoring and Management (RMM) tool installation activities. It looks for common patterns used by adversaries to deploy RMM agents, including silent MSI installations from HTTPS URLs, batch/VBS scripts performing administrative privilege checks prior to silent execution, and PowerShell commands utilizing 'Start-Process' with elevated privileges to download and execute files from the internet.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
102
Page 24 of 1866