Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects instances where PowerShell processes initiate outbound WebDAV connections, potentially to download or stage malicious DLLs. The detection rule correlates network activity involving WebDAV indicators (e.g., DavWWWRoot) with subsequent local file creation events for DLL files within WebDAV-related folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
005
Flags anomalous volume of Entra ID sign-ins using the device-code authorization grant, matching the Kali365 phishing-as-a-service technique (sold on Telegram, ~$250/month per FBI PSA) that captures Microsoft 365 OAuth tokens through the legitimate device-code flow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
502
Detects tenant-level enablement of Microsoft Teams external/federated access or addition of an unfamiliar external domain shortly before a spike in inbound Teams calls to helpdesk/IT-support-tagged users — models CrowdStrike's 2026 Financial Services Threat Landscape Report on 'Mutant Spider,' the most active threat to financial services, whose primary technique is voice phishing over Microsoft Teams impersonating internal IT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Flags installation of RMM tools (AnyDesk, ScreenConnect, TeamViewer, Atera, Splashtop) on an endpoint shortly after that user's account undergoes a password/MFA reset — matches the post-vishing tooling pattern CrowdStrike attributes to Mutant Spider (loaders including PrionFlaire and SocksLoader) and Scattered Spider.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
202
Detects a suspicious sequence of identity-related operations performed by a single user within a 2-hour window. The chain consists of a password reset, MFA method modification, new device registration, and a subsequent privilege escalation event (such as role assignment or application consent). This pattern is consistent with helpdesk-vishing campaigns often used by threat actors like Scattered Spider to perform full account takeovers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects instances where WScript or CScript (Windows Script Host) spawns PowerShell with common obfuscation and persistence flags, specifically executing in a hidden, non-interactive, headless, and encoded command mode. This pattern is commonly used by malicious scripts (e.g., VBScript or JScript) to execute secondary payloads while minimizing visual indicators on the host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
306
Detects the spawning of suspicious child processes (powershell, cmd, node, wscript, cscript) by dependency management utilities (npm, go, terraform). Attackers often leverage malicious packages or configurations during the build or install phase to execute arbitrary code. The rule also monitors for suspicious command-line execution patterns, such as detached 'go run' operations, which may indicate malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects instances where the Terraform process initiates a 'go run' command or references specific Go-based provider source files, which may indicate an attempt to run malicious or unauthorized Go code within the infrastructure-as-code environment. This behavior is indicative of supply chain compromise where providers are leveraged to execute arbitrary logic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the creation of a new local user account named 'ops' or an account with 'full' group privileges on MikroTik RouterOS. This rule is designed to identify potential persistence mechanisms following the exploitation of MikroTrick vulnerabilities (CVE-2026-67279/CVE-2026-86060), often indicated by anomalous prior login patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects unauthorized export and outbound exfiltration of MikroTik RouterOS .rif diagnostic files. These files contain sensitive device configuration data and are often targeted during the final stage of the 'MikroTrick' attack chain, following administrative credential compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects attempts to perform path traversal attacks against the MikroTik RouterOS WebFig interface via the jsproxy endpoint. The rule monitors HTTP proxy traffic for directory traversal sequences (e.g., '../' or URL encoded equivalents) within the query parameters of requests directed to the jsproxy URI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects instances where explorer.exe (the Windows Shell) spawns a PowerShell process with suspicious flags, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the Graphalgo Go-based remote access trojan (RAT) sending an initial system report containing device and user information to the Slack API. This activity occurs during the initial check-in phase before establishing a primary command and control channel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects critical log entries on MikroTik RouterOS devices that contain 'flagged' status messages following a system upgrade or maintenance. This pattern is indicative of potential post-exploitation activity or post-update integrity warnings identified in recent vulnerabilities affecting RouterOS.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects high-risk destructive database operations (DROP, TRUNCATE, or UPDATE) on sensitive tables executed within six hours of a large outbound data transfer from the same host, a pattern indicative of anti-forensic database wiping following data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects the 'ClickFix' technique where a user is socially engineered into copying a malicious command to their clipboard and pasting it into the Windows Run dialog (Win+R). The rule monitors for powershell.exe spawned by explorer.exe containing specific social engineering keywords or typical fileless download-execute patterns like 'irm', 'iex', or 'Invoke-RestMethod'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
302
KQL Query from file: TerminalFix Detection
avatar
Steven Lim@KQLWizard
avatar
SlimKQL 2026
27 days ago
1492230
This rule detects the suspicious use of signed Windows binaries (rundll32.exe, regsvr32.exe, mshta.exe, msiexec.exe) to execute remote content via URLs or scripts, or when triggered by common office applications and browsers. This behavior is often indicative of living-off-the-land (LotL) techniques used for download/execution of payloads or bypassing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
202
This rule detects potential Pass-the-Hash lateral movement by identifying NTLM network logons (Event ID 4624, LogonType 3) on a host that lack a preceding interactive (LogonType 2, 10) or Kerberos-authenticated logon, coupled with subsequent access to sensitive administrative shares (Event ID 5140) by the same user account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects the execution of PowerShell with suspicious command-line patterns indicative of obfuscation or malicious intent, including encoded commands, Base64 decoding, IEX combined with common download cmdlets, and specific obfuscation techniques like backtick concatenation, character casting, or variable concatenation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects anomalous Kerberos ticket requests that are characteristic of Golden Ticket attacks. The rule flags the use of weak encryption types (e.g., RC4) commonly used in forged tickets even in AES-enforced environments, and direct requests for the KRBTGT service account outside of legitimate ticket renewal operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
402