Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of the Rubeus tool, a C# toolkit used for interacting with the Kerberos protocol. The rule specifically monitors command-line arguments and process names associated with common Kerberos exploitation tasks such as Kerberoasting, Golden/Silver Ticket forging, and ticket manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
203
This rule detects unauthorized attempts to perform Active Directory replication requests (DCSync) by monitoring for specific Event IDs (4662), activity types (DsGetNCChanges, DRSUAPI), and known Directory Replication Service (DRS) UUIDs. It specifically flags requests originating from non-Domain Controller assets or workstations, which is a common indicator of credential dumping via tools like Mimikatz.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
This rule monitors for execution patterns associated with the Evil-WinRM tool, a common post-exploitation framework used for remote command execution via WinRM. It identifies suspicious command-line arguments in PowerShell, the creation of configuration files typical of the tool, and network connections to WinRM ports initiated by common execution binaries like PowerShell or Ruby.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
103
Detects file creation, modification, or renaming events initiated by ScreenConnect (ClientService.exe or WindowsClient.exe) that are not accompanied by associated user confirmation, consent, or file transfer events. This can indicate an unauthorized or silent file manipulation by a remote actor using the ScreenConnect tool.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
203
Detects multiple defense evasion techniques typically associated with the Monkey ransomware family, including clearing Windows Event Logs, clearing PowerShell command history, tampering with AMSI and ETW, modifying Microsoft Defender exclusions, and disabling Task Manager or CMD via registry keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects the execution of the Rubeus tool, a widely used offensive security tool for Kerberos manipulation, including ticket requests, pass-the-ticket, and credential dumping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
203
This rule detects potential credential dumping activities by monitoring for the execution of Mimikatz or command-line arguments associated with credential extraction (e.g., 'sekurlsa::logonpasswords'). Additionally, it monitors for suspicious process access attempts to 'lsass.exe' with specific high-privileged access masks often used by credential dumping tools to read process memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
103
This rule detects suspicious child processes, such as shells and system utilities, spawned by PaperCut application processes (pc-app.exe, pc-app-service.exe) or associated Java/Tomcat service components. This pattern is commonly observed during exploitation attempts targeting PaperCut Print Management software, where attackers use web services to gain command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
103
Detects potential SQL injection attempts by monitoring for 'INSERT INTO' SQL commands executed via command-line arguments. The rule specifically looks for operations targeting user or role tables and including administrative keywords, originating from database or application-related processes like mysql or java.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
This rule detects file access events targeting sensitive files such as credential stores, configuration files (e.g., .env, config.yaml, wallet.dat), and AWS credential files. This is indicative of an adversary searching for stored secrets or configuration data to facilitate further lateral movement or privilege escalation. The rule excludes common developer tools like code editors and file explorers to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects when ScreenConnect client processes (ClientService.exe or WindowsClient.exe) spawn child processes that are not part of the standard ScreenConnect application suite. This behavior is indicative of unauthorized use of remote access tools for command execution or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
This rule performs a hunting activity across multiple telemetry sources (Network, Email, Endpoint) to detect known indicators of compromise (IOCs) associated with Anthropic threat intelligence reporting (September 2026). It looks for specific malware file names, command-line patterns, service installations, phishing email addresses, and C2 communication URLs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
607
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
000
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
000
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
000
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
000
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
Detects lateral movement (SMB, RDP, WinRM) performed by a host within 5 minutes of communicating with specific commercial LLM APIs. This rule targets behaviors indicative of automated lateral movement driven by an LLM-based C2, excluding common administrative tools, standard business hours, and frequently used processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
000
Page 254 of 1871