Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects web proxy requests that resemble phishing attempts targeting Apple Activation Lock. The rule identifies URLs containing specific Apple-related keywords in combination with common phishing URL paths, while filtering out legitimate Apple support documentation pages.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the presence of the i-Realm companion tool associated with the AnonyMousKIT PhaaS platform, which is designed to bypass iOS Activation Lock features.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects a sequence of suspicious identity activities indicative of a post-account-takeover pivot. The rule identifies a user profile engaging in corporate VPN SAML SSO probing, triggering a MFA enrollment interrupt in Azure, and subsequently accessing multiple Microsoft 365 applications (Azure Portal, OfficeHome, SharePoint) within a 30-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
102
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
105
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
003
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
103
This rule detects suspicious activity associated with Redis server processes attempting to write to SSH 'authorized_keys' files or executing commands (such as BGREWRITEAOF or directory reconfiguration) commonly used by attackers to inject malicious SSH public keys into a Redis installation for persistent remote access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects a multi-stage attack chain involving the download, extraction, permission modification, and execution of the XMRig cryptocurrency miner on Linux systems. The rule specifically monitors for common staging patterns in /tmp and the use of known mining-related CLI arguments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the creation or modification of a file within the /etc/cron.d/ directory, followed shortly by a Bash process invocation using /dev/tcp redirection. This pattern is commonly used by attackers to achieve persistence via cron and establish reverse shells, bypassing potential limitations of default system shells that do not support /dev/tcp syntax.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects a post-compromise pattern on a WordPress site where an attacker, after an initial login, rapidly accesses multiple sensitive administrative pages (plugins.php, profile.php, etc.) within a short window, suggesting nonce harvesting. This activity is correlated with the subsequent creation of a suspected webshell file named 's.php'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects network traffic consistent with the XMRig cryptocurrency mining tool communicating with a Monero mining pool via TLS. The rule identifies specific SNI domains and direct connection attempts to known proxy IP addresses associated with cryptomining activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
003
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
003
Detects anomalous external traffic patterns indicative of automated API reconnaissance. The rule flags high-frequency requests from a single IP targeting a diverse set of API endpoints, particularly when characterized by a mixture of successful (200), unauthorized (403), or not found (404) status codes, or repeated attempts to access sensitive management/administrative API paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects a sequence of activity indicative of beacon-like behavior: initial domain reconnaissance using commands such as 'net', 'systeminfo', or 'nltest', followed by the execution of 'rundll32.exe' without command-line arguments, and subsequent LDAP (port 389) communication to a domain controller, all occurring within a short timeframe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
102
Detects instances where browser processes (Chrome or Edge) are spawned by smartscreen.exe and subsequently access sensitive browser storage files such as Login Data, Cookies, or Local State. This pattern is indicative of a process injection or masquerading chain used to extract credentials or session data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
202
Detects potential lateral movement or pivot attempts by correlating repeated failed RDP logons (RemoteInteractive) against sensitive targets (Domain Controllers, File Servers, Backup Servers) with concurrent security tool blocks (e.g., Microsoft Defender Antivirus, Exploit Guard) on the originating beachhead device within a 4-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
302
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
102
This rule detects potentially malicious process execution chains where VBScript or unknown/suspicious binaries (such as ProfileQuickHost.exe) are used to launch Node.js processes, specifically targeting JavaScript files or VBScript agents. This pattern is often associated with the execution of remote access trojans (RATs) or custom malware loaders.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
15 days ago
005
Detects high-volume credential brute-forcing activity targeting Dahua IP camera administrative interfaces (Ports 80/37777). The rule identifies a pattern of multiple connection failures across multiple distinct targets followed by a successful connection, which is highly characteristic of automated credential stuffing or password spraying attacks against embedded IoT devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003