Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects rare or infrequent network connections to common VPN and tunneling ports (e.g., 500, 4500, 1194, 1723) initiated by known VPN clients or web browsers. This rule identifies potential unauthorized external remote access or tunneling behavior by baselining against connections seen in the previous 30 days and filtering for low-frequency events.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
27 days ago
6011
Detects techniques used by SloppyRAT, including indirect NTDLL syscalls bypassing API hooks (Hell's Gate style), and the use of DJB2 API hashing for NtAllocateVirtualMemory and NtCreateThreadEx. It monitors for CallTrace patterns indicating unbacked memory calls into ntdll.dll, detection of hardcoded DJB2 hash constants, or the presence of the B8 (mov eax, imm32) instruction followed by the 0F 05 syscall opcode.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects evidence of the Alinubx.sys kernel driver being loaded or interacted with via its device interface using a specific IOCTL (0x222024). This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, effectively bypassing Windows Protected Process Light (PPL) protections.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects evidence of the Alinubx.sys kernel driver being loaded or interacted with via its device interface using a specific IOCTL (0x222024). This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, effectively bypassing Windows Protected Process Light (PPL) protections.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule detects the execution of the legitimate Microsoft Visual Studio CoreCLR Debugger (vsdbg.exe) from an unauthorized file location. This behavior is indicative of masquerading, where the executable is renamed to appear as an installer to sideload a malicious companion vsdbg.dll, a technique observed in the Rapuncel/BoryptGrab campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the creation of a PowerShell process that identifies itself as being spawned by explorer.exe, while the process ID (PID) and parent process ID (PPID) relationship indicates inconsistency, often characteristic of the PSSpoof technique used by malware like SloppyRAT to evade detection by spoofing the process tree.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects attempts by malicious software, specifically SloppyRAT, to query or modify Microsoft Defender settings by interacting with WMI classes like MSFT_MpPreference or MSFT_MpComputerStatus. This activity is indicative of efforts to disable security controls such as real-time monitoring to facilitate further malicious actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects evidence of SloppyRAT employing the Hell's Gate technique, specifically the resolution and indirect invocation of low-level NT system calls (e.g., NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx) designed to bypass EDR user-mode API hooking during process injection activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects instances where a user signs in via a Device Code authentication flow and subsequently adds a member to a highly privileged group (e.g., Domain Admins, Global Administrators) within one hour. This behavior is indicative of potential account compromise where an attacker uses an OAuth device code flow to establish access and then escalates privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the mass termination of multiple security-related processes on a host within a short timeframe, correlated with the presence of specific driver modules potentially associated with security software interference or evasive behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule monitors network and event logs to detect instances where a single user account, logged into a specific host, initiates connections to two or more distinct, potentially suspicious remote IP addresses. This pattern of multi-destination connection activity may indicate command and control communication, scanning behavior, or data staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects suspicious device registration or join events occurring within 60 minutes of a Device Code authentication flow. This pattern is consistent with the ARToken post-compromise technique, where an adversary uses an intercepted authentication code to register a new device to maintain persistent access to an Entra ID (Azure AD) environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects instances where processes other than legitimate PowerShell binaries load the .NET Common Language Runtime (clr.dll) or the System.Management.Automation assembly. This behavior is often indicative of 'PowerShell-less' execution techniques, where adversaries interact with the PowerShell engine directly from arbitrary host processes to execute malicious code or scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the deletion of Google Chrome browser extension settings from the Windows Registry. Adversaries often target the 'extensions.settings' registry value under 'PreferenceMACs' to disable security extensions, force the installation of malicious extensions, or tamper with browser-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule detects the installation of a new Windows service (Event ID 7045 or 4697) with an 'auto start' configuration that is immediately followed by the termination of multiple processes (either 'services.exe' or the service's own image file) within a 60-minute window on the same host. This pattern can indicate an unstable or malicious service deployment that causes system instability or performs rapid cleanup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule detects indicators of the Rapuncel browser injection by monitoring for the creation of a known malicious DLL hash on disk, identifying non-standard parent processes invoking elevation_service.exe, and detecting the loading of unrecognized DLLs into Google Chrome or Microsoft Edge browser processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects potential UAC bypass attempts using COM Elevation Monikers or the misuse of ServiceModelReg.exe, often associated with process hollowing techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects potential reflective code loading or memory injection attempts within Python interpreter processes (pythonw.exe, ipy.exe). The rule monitors for processes that lack a valid module path or file path on disk while referencing known indicators of malicious memory-based loading, such as 'hostfxr.dll' or specific suspicious strings like 'DLLMemLoader'. This technique is often used to execute payloads directly in memory to evade file-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule detects suspicious process activity in interpreters (ipy.exe, pythonw.exe) or rundll32.exe involving multiple, rapid consecutive calls to sensitive memory management and thread creation functions (e.g., NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx). The logic specifically monitors for a high frequency of distinct, powerful Windows API calls, which is often indicative of reflective code injection or process hollowing, including techniques like 'Hell's Gate' or those associated with SloppyRAT, and accounts for potential .NET/hostfxr-related execution vectors.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the execution of processes containing indicators associated with Alinubx or the string 222024, which are potentially linked to malicious software or unauthorized tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule detects the execution of the Visual Studio Debugger (vsdbg.exe) from suspicious locations such as Downloads, Temp, or Desktop directories. Executing development tools from these user-writable directories is often indicative of an adversary attempting to use legitimate debugging tools to facilitate process injection or malicious activity. The rule excludes legitimate executions located within the official Microsoft Visual Studio installation directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Page 241 of 1871