Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects modifications to the Chrome browser's registry key that stores extension settings. Adversaries may modify these registry keys to silently install, enable, or configure malicious browser extensions for persistence and credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the creation of a new Windows service using the service control manager command-line utility (sc.exe). This command is commonly used by attackers to achieve persistence by creating services that execute malicious binaries at startup, or to run processes with SYSTEM privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule detects the execution of the legacy finger.exe utility when spawned by common user-facing applications (e.g., browsers, shells, explorer). The detection specifically looks for instances where the command line includes an '@' character, indicating an attempt to query information from a remote host, while excluding standard localhost queries. This pattern is often associated with reconnaissance activity or enumeration of remote users/systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
102
This rule detects the execution of the legacy finger.exe utility when spawned by common user-facing applications (e.g., browsers, shells, explorer). The detection specifically looks for instances where the command line includes an '@' character, indicating an attempt to query information from a remote host, while excluding standard localhost queries. This pattern is often associated with reconnaissance activity or enumeration of remote users/systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the execution of IronPython or generic Python interpreters where the command line contains suspicious obfuscation patterns, including base64-encoded strings, zlib compression/decompression, and the use of the subprocess module. This pattern is commonly used by adversaries to execute hidden or obfuscated malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects DNS resolutions for Microsoft Graph API endpoints (graph.microsoft.com) initiated by processes other than standard, expected Microsoft applications (e.g., Outlook, Teams, OneDrive). This behavior may indicate unauthorized processes or potential beaconing/C2 activity masquerading as legitimate Microsoft cloud service traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects two distinct methods used for persistence and execution: 1) Addition of 'rundll32' to Windows Registry Run keys, often used to execute malicious code upon logon. 2) Creation or modification of COM InprocServer32 registry keys, a technique known as COM Hijacking used to load malicious DLLs when a legitimate COM object is initialized.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the invocation of common command-line interpreters (PowerShell or Windows Command Shell) via process creation events. This is a broad detection for administrative shell activity, which may also indicate malicious script execution or manual adversary interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the loading of the kernel driver 'Alinubx.sys', identified as a renamed instance of the 'CcProtect.sys' driver. This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, specifically observed in the context of Rapuncel infostealer campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects outbound network activity on TCP port 79 (finger) initiated by a client to the domain 'finger.linked4x.com'. This behavior is associated with the SloppyRAT 'ClickFix' campaign, where attackers use social engineering to trick users into executing commands, leading to payload staging and tool retrieval.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
avatar
Arnold Chan@slaz
avatar
SlimKQL
28 days ago
8014
Detects the execution of 'bun' during a Node.js package installation process (npm or node). This behavior can be indicative of a supply chain attack where malicious actors attempt to leverage alternative runtimes during the 'preinstall' phase or package installation to execute arbitrary code or bypass security controls typically associated with standard Node.js installations.
avatar
Arnold Chan@slaz
avatar
Hunters
28 days ago
6014
Detects the execution of PowerShell with encoded commands or Base64 decoding attempts initiated by common Windows shell applications (explorer, mshta, wscript, cscript) launched from an LNK file. This pattern is commonly associated with malicious LNK shortcuts used as initial access vectors or stage-two downloaders.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
103
This rule detects potential lateral movement by monitoring successful network logons using NTLM authentication across multiple distinct destination hosts within a short time window. It calculates the frequency of connections to unique hosts to identify anomalous, rapid traversal through a network by a single user account, excluding known system accounts.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
25 days ago
207
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
003
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
003
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
208
Detects malformed HEIF/HEIC image files with anomalous ftyp/box structure consistent with the libheif memory corruption exploit (CVE-2026-32882) used against Discourse forum image upload endpoints
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
002
This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
002
This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
002
This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
002
Page 242 of 1871