Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects activity associated with MovieReaper campaign including process, file, and network indicators
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
003
Detects the execution of rundll32.exe where the command line points to a DLL file located on a remote WebDAV share (using the 'davwwwroot' path syntax). This technique is often used to execute malicious payloads while bypassing local disk protections.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
101
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
003
Detects the installation of a new kernel-mode service using system utilities like sc.exe, cmd.exe, or powershell.exe, which is a common indicator of a Bring Your Own Vulnerable Driver (BYOVD) attack intended to gain kernel-level privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of known NetSupport Manager remote access tool binaries from locations outside of the official installation directories. This behavior is indicative of unauthorized use or persistence of remote management software, often used as a RAT by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
101
Detects unusual network connections over port 445 involving SMB named pipes commonly associated with lateral movement tools or P2P beaconing. The rule identifies communication through suspicious or generic pipe naming conventions that deviate from standard system process behavior (e.g., lsass, services, svchost, System).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the loading of amsi.dll by common .NET loader processes, which may indicate attempts to patch or bypass the Antimalware Scan Interface (AMSI) in memory. The rule monitors for image load events of amsi.dll and correlates them with process creation events of known loaders such as powershell.exe, rundll32.exe, and others.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects processes attempting to load ntdll.dll or utilizing DLLs in a manner that may indicate the use of indirect syscalls, a technique used by malware to bypass EDR/AV user-mode API hooking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects potential PIVOTPIPE activity by correlating AMSI patching indicators with anomalous memory protection changes. It identifies processes that perform frequent transitions to PAGE_EXECUTE_READWRITE or PAGE_NOACCESS, which is indicative of memory-based obfuscation techniques used to evade memory scanning and detection during sleep cycles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
000
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
000
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
003
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
003
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
000
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
000
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
Page 245 of 1871