Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects instances where a non-administrative user grants an OAuth application consent to access high-privilege Microsoft Graph scopes, such as 'Mail.Read', 'Directory.ReadWrite.All', or 'offline_access'. This pattern is frequently used in consent phishing attacks to maintain persistent access to sensitive cloud resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects anomalous lateral movement behavior where a single user account authenticates via NTLM to three or more distinct target hosts within a short time window (10 minutes). This pattern of rapid, broad authentication is a strong indicator of a Pass-the-Hash (PtH) attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects unauthorized directory service access requests (Event ID 4662) utilizing the 'DS-Replication-Get-Changes' or 'DS-Replication-Get-Changes-All' extended rights GUIDs. These rights are required for the DCSync technique used by tools like Mimikatz or Impacket to replicate Active Directory data. The rule specifically flags when such requests originate from a non-domain controller host, which is a strong indicator of credential theft or unauthorized replication attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
This rule detects potential lateral movement via WMI by identifying two distinct suspicious behaviors: WmiPrvSE.exe spawning unexpected child processes (excluding common legitimate processes) or the usage of wmic.exe and PowerShell cmdlets (Invoke-WmiMethod, Invoke-CimMethod) to execute processes on remote systems, as indicated by command line arguments specifying target nodes or computer names.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects suspicious PowerShell execution patterns involving encoded commands, hidden window styles, or common download cradles combined with code obfuscation techniques. This rule monitors PowerShell ScriptBlock Logging (Event ID 4104) for combinations of indicators often used by threat actors to evade detection, such as Base64-encoded strings, hidden execution flags, network download utilities, and script obfuscation techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects unauthorized or suspicious use of Windows Management Instrumentation (WMI) for lateral movement and remote code execution. The rule monitors for common WMI exploitation vectors, including the use of wmic.exe for process creation, PowerShell or C# invocations of WMI/CIM methods (such as Win32_Process Create), WMI event subscription registration for persistence, and the execution of mofcomp.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
202
This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys where the configured value points to a file located in common user-writable or temporary directories (AppData, Temp, ProgramData) with an executable extension (.exe, .dll, .scr, .bat, .vbs, .ps1, .cmd). This pattern is a common technique used by adversaries to establish persistence by ensuring malicious code executes automatically upon user login or system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
502
This rule detects potential DNS tunneling activity by identifying DNS requests with suspicious characteristics, such as the use of TXT/NULL query types, high-entropy subdomains, or oversized queries. It further aggregates these suspicious requests per parent domain and flags scenarios where a high volume of requests or unique subdomains are observed, indicating possible data exfiltration or C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
202
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
002
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
002
KQL Query from file: Network detection - C2 domains and static key
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
002
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
002
KQL Query from file: JivaChat Installer - Full Chain
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
002
KQL Query from file: JivaChat Installer - Full Chain
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
002
KQL Query from file: JivaChat Installer - Full Chain
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
002
Detects execution of encoded commands in macOS terminal environments that originate from clipboard content mimicking a reCAPTCHA verification process. This pattern often involves users being social-engineered into pasting a malicious string that decodes a payload and pipes it directly into a shell interpreter (sh/bash/zsh). The rule monitors for the co-occurrence of base64/openssl decoding commands and shell execution pipes, while filtering out known legitimate software installation patterns.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
101
Detects execution of encoded commands in macOS terminal environments that originate from clipboard content mimicking a reCAPTCHA verification process. This pattern often involves users being social-engineered into pasting a malicious string that decodes a payload and pipes it directly into a shell interpreter (sh/bash/zsh). The rule monitors for the co-occurrence of base64/openssl decoding commands and shell execution pipes, while filtering out known legitimate software installation patterns.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
101
Detects HTTP POST requests directed to the URI path '/api/credentials' over the non-standard TCP port 8133, which is indicative of AMOS (Atomic macOS) Stealer exfiltrating stolen credentials to a C2 server.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
001
Detects HTTP POST requests directed to the URI path '/api/credentials' over the non-standard TCP port 8133, which is indicative of AMOS (Atomic macOS) Stealer exfiltrating stolen credentials to a C2 server.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
101
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
101
Detects inbound Microsoft Teams calls or chats originating from an external or federated tenant where the caller's display name mimics internal IT support or helpdesk personnel, a technique used in social engineering and vishing campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
005