Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
000
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
Detects the execution of multiple distinct host reconnaissance commands (e.g., systeminfo, whoami, ipconfig, AV/EDR checks, and domain enumeration) within a short window (10 minutes) originating from the same parent process. This pattern is characteristic of automated reconnaissance collection, often performed during the initial phases of an attack or as part of a C2 workflow. The rule includes exclusions for common administrative, monitoring, and RMM tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
000
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
Detects delivery and execution artifacts associated with the BlueMoon CVE-2026-85046 V8 type-confusion exploit. The rule monitors for known exploit-related file names (e.g., driver-html.js) and characteristic string indicators (e.g., v8ctf_exp_attempt, addrof, fakeobj) across file system, process execution, and network telemetry.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
15023
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
avatar
Arnold Chan@slaz
avatar
Hunters
28 days ago
6012
This rule detects potential malicious activity by monitoring for known malicious file hashes (MD5) across file and process events, and correlating them with known Command and Control (C2) infrastructure communication patterns, including specific IP addresses and URI paths.
avatar
Arnold Chan@slaz
avatar
SlimKQL
23 days ago
103
Detects the presence or execution of a specific file hash associated with a known malicious campaign (KREMLIN/REF9334) that leverages a signed SentinelOne binary. This indicates potential abuse of trusted code-signing to bypass security controls.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
24 days ago
204
Detects Remote Desktop Protocol (RDP) connections established over known suspicious high ports or to specific remote IP addresses associated with known C2 operator infrastructure (SpiceRAT). This behavior indicates potential remote interactive access by an adversary.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
003
Detects the loading of 'libcurl.dll' or related DLL patterns from suspicious directories such as '\Microsoft\Crypto\RuntimeBroker\', often associated with process masquerading or side-loading activities. The rule also monitors for the execution of suspicious binaries ('Tax_Notice_45594.exe') or binaries that mimic 'Notepad++' metadata from within these paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
24 days ago
204
Detects outbound network connections to known command-and-control (C2) infrastructure associated with SpiceRAT, including specific malicious IP addresses and domain names used for decoy content delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
003
This rule detects outbound network connections from internal devices to a list of known malicious IP addresses associated with adversary command and control infrastructure. The rule specifically monitors connections over common ports, potentially indicating established communication with malicious servers.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
24 days ago
104
Detects outbound network connections to 'acrobat-updater.com' involving suspicious API paths that mimic the Adobe Acrobat updater. This may indicate an attempt by an adversary to masquerade malicious command and control or data exfiltration as legitimate update traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
24 days ago
204
Detects attempts to perform a DCSync attack by monitoring for Windows Event ID 4662 where sensitive Directory Replication Service (DRS) rights are requested. This attack pattern, often associated with tools like Mimikatz, allows an adversary to pull password data from Active Directory. The rule excludes requests from known domain controller accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects the execution of PowerShell with specific command-line arguments (-NonInteractive, -NoProfile, -Command) often used by the Bird Agent backdoor or similar malicious scripts to execute code silently without user intervention or profile configuration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects the creation of suspicious DLL or ASPX files within Microsoft Exchange or IIS directories that are associated with the GhostContainer backdoor, commonly used by the NightEagle threat actor for maintaining persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects DCSync activity, a method of credential dumping, by identifying DRSUAPI 'GetNCChanges' replication requests originating from a host that is not a recognized Domain Controller. The rule uses Active Directory replication GUIDs, explicit operation logs, and enriches host data to filter for illegitimate sources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects unauthorized child processes spawned by ScreenConnect client binaries. The rule specifically looks for files created or modified within 60 seconds prior to execution, which is indicative of attackers leveraging an authentication bypass vulnerability (CVE-2026-84869) to transfer and execute malicious payloads via an active remote access session without requiring additional user interaction or authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects a multi-stage infection chain involving communication with known malicious infrastructure ('mnoskemp.beer'), staging and extraction of password-protected archives using '7za.exe' in temporary directories, installation of a spoofed OBS Studio MSI package, and subsequent DLL side-loading of malicious libraries (e.g., 'obs.dll', 'WSql-2.dll') by the 'obs64.exe' process when initiated from outside legitimate installation paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
000
This rule detects potential exploitation attempts against PaperCut servers by identifying high-frequency, consistent-interval network requests directed at PaperCut-specific URI patterns and ports, or associated with known vulnerability identifiers (CVE-2026-81578, CVE-2026-82078). The rule employs statistical analysis to identify potential automated scanning or exploitation activity, filtering out known geographic regions associated with lower-risk or irrelevant traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Page 255 of 1871