Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the creation of a scheduled task using schtasks.exe that involves 'keyroll' in the command line. This pattern specifically flags tasks associated with the 'rnpkeys.exe' utility or tasks being created within 'keyroll' directories, which may indicate the deployment or maintenance of unauthorized key management or persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
106
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
202
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
102
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
002
Detects the modification of the 'DisableRestrictedAdmin' registry key via 'reg.exe'. This registry setting, when disabled (set to 0), allows the use of 'Restricted Admin' mode for Remote Desktop connections, which can be leveraged to bypass certain credential protections or enable lateral movement using high-privilege credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
102
Detects the 'mscopilot.exe' binary performing token manipulation operations (DuplicateTokenEx, ImpersonateLoggedOnUser, SetThreadToken) followed by the creation of a new process with a different security context (CreateProcessAsUserW) within a five-minute window, indicative of C2 agent functionality.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
202
Detects anomalous lateral movement behavior where a user account authenticates via NTLM (Logon Type 3) to at least three different hosts within a 10-minute window and subsequently accesses administrative network shares (ADMIN$ or C$) on one or more of those target systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
702
Detects the creation of web scripts (aspx, php, jsp) in typical web server directories followed by suspicious shell activity (cmd, powershell, or shell execution) originating from web server processes within a 10-minute window. This behavior is indicative of a web shell being dropped and subsequently utilized for command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
Detects potential exploitation attempts of the Zerologon vulnerability (CVE-2020-1472) by monitoring for Domain Controller machine account password resets (Event 4742) targeting DC computer accounts, and insecure Netlogon RPC channel events (Event 5829) triggered when vulnerable clients or tools attempt connections.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
Detects the Print Spooler service (spoolsv.exe) spawning a shell/script interpreter or rundll32.exe as a child process, or loading a DLL from a driver-store/temp/ProgramData path — the process-injection and arbitrary-DLL-load pattern characteristic of PrintNightmare (CVE-2021-34527) exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
302
Detects the WMI provider host process (WmiPrvSE.exe) spawning common command-line or system administration tools such as cmd.exe, powershell.exe, or rundll32.exe. This activity is correlated with a preceding network connection to the host on port 135 (DCOM/WMI), which is indicative of lateral movement using WMI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
202
This rule detects potential Golden Ticket activity by identifying Kerberos TGS requests (Event ID 4769) that lack a corresponding prior TGT request (Event ID 4768) for the same user and IP address. This behavior is characteristic of offline forged Kerberos tickets where an attacker uses a compromised KRBTGT hash to create authentication tickets without interacting with the Key Distribution Center for the initial TGT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
302
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
avatar
SlimKQL
8 days ago
002
Detects NTLM network logons (LogonType 3 or 9) which often result from a host resolving an attacker-supplied UNC path (e.g., \host esource) during forced authentication attacks. This rule monitors Windows Security Event ID 4624 to identify incoming NTLM-based network authentication requests, excluding local system logons.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
103
Detects modifications to the Windows Subsystem for Linux (WSL) InstallLocation registry key.
Attackers can modify this registry key to redirect the execution flow of legitimate WSL processes (wsl.exe or bash.exe) to a malicious payload, acting as a proxy execution and defense evasion technique.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
6 days ago
001
This rule identifies installations of TeamViewer software that are vulnerable to specific CVEs (CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371) by analyzing the 'DeviceTvmSoftwareInventory' dataset. It checks for versioning patterns against known vulnerable build numbers across Windows, Linux, and macOS platforms to pinpoint systems requiring patching.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
8 days ago
302
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
002
Page 25 of 1866