Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

KQL Query from file: CSuite Campaign - Known Payload File Hash Hunt
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
202
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
203
This rule detects malicious activity associated with the Bazinga macOS backdoor, specifically focusing on the clearing of TCC privacy permissions, the staging of keychain and browser data using 'ditto', and the subsequent exfiltration of this data to a remote host via 'curl'.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
202
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
002
Detects potential password spraying activity in Azure Active Directory by identifying a single source IP address that authenticates against multiple distinct user accounts within a short time frame. The rule flags instances where there are numerous authentication attempts across many users, characterized by a low per-user failure count followed by at least one successful authentication, which is indicative of a successful password spray attempt.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
202
Detects potential password spraying activity in Azure Active Directory by identifying a single source IP address that authenticates against multiple distinct user accounts within a short time frame. The rule flags instances where there are numerous authentication attempts across many users, characterized by a low per-user failure count followed by at least one successful authentication, which is indicative of a successful password spray attempt.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
102
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
102
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
202
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
202
This rule detects potentially malicious activity originating from Microsoft Word (WINWORD.EXE). It monitors for two specific patterns: the creation of script files (.bat, .vbs, .cmd) with GUID-based filenames in non-temp directories, and the creation or execution of files matching known malicious hashes associated with the Hookedge malware family.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
5048
KQL Query from file: ThreatFox IOC Hunt feed
avatar
Ankit Mehta@Secvyn
avatar
Hunters
10 days ago
001
This rule detects potentially malicious activity involving LNK files being modified, created, or renamed in common locations (Desktop, Quick Launch, Start Menu) correlated with the creation of files ending in '.backup' within 30 minutes. It also independently detects the presence or execution of 'VLCAssistant.exe', which may indicate unauthorized launcher activity or masquerading.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects Microsoft Entra ID service principal (app-only) sign-in events where an application accesses a resource or tenant that has not been observed in the previous 30 days. This is often an indicator of cross-tenant impersonation abuse or credential misuse, particularly related to Actor Tokens.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
102
This rule detects inbound emails where the sender domain matches the recipient domain (internal-looking), but the message authentication (SPF/DKIM/DMARC as indicated by CompAuth status) failed or was not performed. This is indicative of abuse of Exchange Online 'Direct Send' or similar unauthenticated relay methods to spoof internal identities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
202
This rule detects large-scale, non-interactive password-spraying campaigns targeting Microsoft Entra ID (Azure AD) accounts. It specifically identifies anomalous login behavior originating from Azure CLI or similar non-interactive clients, where a single source IP attempts to authenticate against a large number of distinct user accounts with a low number of failures per user within a short timeframe, characteristic of 'low-and-slow' password spraying.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects anomalous, high-frequency, multi-channel probing of AI agent input surfaces. The rule identifies external actors sending instruction-injection style keywords across different communication channels (e.g., email, Teams, calendar) within a short window, which may indicate an attempt to identify and manipulate an organization's autonomous agents. Covers T1595.002
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
002
Detects anomalous, high-frequency, multi-channel probing of AI agent input surfaces. The rule identifies external actors sending instruction-injection style keywords across different communication channels (e.g., email, Teams, calendar) within a short window, which may indicate an attempt to identify and manipulate an organization's autonomous agents. Covers T1595.002
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
102
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
102
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
002
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
202
Detects potential AI-targeted cloaking, a technique where a web server serves different content to AI crawlers versus human users, identified by comparing HTTP response sizes or hashes across session logs. The rule uses Microsoft Sentinel's ASIM Web Session schema to correlate web requests, identifying discrepancies that suggest malicious or evasive intent. Covers T1036 & T1027
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
202