Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
003
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
This rule detects potential attempts to abuse a Trusted Domain Object (TDO) to traverse a one-way Active Directory trust. It identifies suspicious activities such as Kerberos ticket requests (AS-REQ/TGS-REQ) targeting trust accounts (inter-realm indicators) or DCSync-style replication requests targeting the TDO object to extract domain secrets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
405
This rule detects potentially malicious activity targeting Microsoft Entra Connect (formerly Azure AD Connect) servers. It identifies the execution of known credential harvesting tools like AADInternals or attempts to access/extract the ADSync database files and encryption components. Such actions indicate an attempt to gain unauthorized access to synchronized identities, local domain credentials, or cloud synchronization service accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
505
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
203
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
103
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
003
Detects the creation of Windows services using sc.exe, powershell.exe, or cmd.exe that reference specific DLL files (winfsp-x64.dll or DukeQt.dll). This behavior is often associated with persistence mechanisms or DLL hijacking/side-loading techniques where a malicious service is configured to load a specific library.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
403
Detects a specific pattern associated with the VioletRAT stage-2 loader, where cmd.exe executes a randomly-named batch file from a temporary directory, which subsequently launches a hidden PowerShell process designed to download or reflectively load a .NET assembly.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
17 days ago
000
Detects a specific pattern associated with the VioletRAT stage-2 loader, where cmd.exe executes a randomly-named batch file from a temporary directory, which subsequently launches a hidden PowerShell process designed to download or reflectively load a .NET assembly.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
17 days ago
000
Detects the creation or modification of registry run keys under HKCU or HKEY_USERS that use the value 'WindowsDefender' to point to an executable located within the AppData directory. This is a common technique used by malware to establish persistence while masquerading as a legitimate security component.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
17 days ago
000
Detects a specific pattern associated with the VioletRAT stage-2 loader, where cmd.exe executes a randomly-named batch file from a temporary directory, which subsequently launches a hidden PowerShell process designed to download or reflectively load a .NET assembly.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
000
IOC sweep against network telemetry for confirmed BengalSEO/MayaBot campaign infrastructure: the Hostmaza backend IP (5.101.140.80), Matomo tracking domains (stats.us3.org, us3.my), named MayaBot C2 domains (cus.cam, dll.lat, us99.org), and the ~170-domain Traffic Distribution System redirector fleet used to funnel victims to payload delivery. The source intel report contains no file hashes (MD5/SHA1/SHA256) -- only IPs, domains, and URLs -- so this sweep is IP/domain-only. Note the much larger corpus of single-use lure-page domains (~1,000 additional indicators) is excluded as too high-churn for static embedding.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
000
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
This rule detects potentially malicious system configuration changes, specifically the suspension or disabling of BitLocker drive encryption via 'manage-bde.exe' and the weakening of SChannel security protocols or ciphers by modifying registry keys. These activities are indicative of an attacker attempting to bypass disk encryption or lower the security posture of network communication.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
26 days ago
708
Detects outbound network connections from internal devices to public IP addresses over standard MQTT (1883) or MQTT over TLS (8883) ports. MQTT is frequently used for IoT communication but can be abused for command and control (C2) or unauthorized data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
305
Detects the use of rundll32.exe to execute comsvcs.dll's MiniDump functionality against the LSASS process, a common technique for dumping credentials. The rule includes behavioral correlation by identifying the same user account executing this pattern on multiple devices within a one-hour window.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
000
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
Page 257 of 1871