Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
000
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
This rule monitors for user interactions with specific domains and URLs known to be associated with suspicious or malicious activity. It aggregates data from multiple sources, including email clicks (UrlClickEvents), device network activity (DeviceNetworkEvents), device browser events (DeviceEvents), and DNS queries (DnsEvents), to identify potential exposure to these indicators of compromise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
105
Detects the use of PowerShell's Start-Sleep cmdlet with a duration of 3 minutes or longer within process command lines. This technique is commonly used by malware, such as ClickFix-style droppers, to bypass sandbox time-based analysis by delaying execution until the sandbox timeout period has elapsed.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
20 days ago
001
Detects execution chains where explorer.exe (acting as the Run dialog host) spawns suspicious processes like mshta.exe, powershell.exe, or cmd.exe with command lines containing URL indicators (http), common payload filenames (rtdx.dat), or specific IP address strings associated with known ClickFix social-engineering campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
20 days ago
001
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
001
Detects the execution of PowerShell commands that utilize a combination of 'iex' (Invoke-Expression) and obfuscated strings typical of download cradles. The rule looks for escaped double quotes inside the command line and specific regex patterns that match common obfuscation techniques used to hide malicious URLs or script components.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
001
Detects the execution of standard Windows command-line utilities (cmd.exe, wmic.exe, powershell.exe, fsutil.exe, vol.exe) used to query local volume information, such as name and serial number. This behavior is frequently associated with environment fingerprinting or sandbox evasion, particularly when executed by suspicious processes like mshta.exe as part of initial infection chains such as ClickFix payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
001
Detects execution chains where explorer.exe (acting as the Run dialog host) spawns suspicious processes like mshta.exe, powershell.exe, or cmd.exe with command lines containing URL indicators (http), common payload filenames (rtdx.dat), or specific IP address strings associated with known ClickFix social-engineering campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
101
Detects the execution of mshta.exe with a command line involving remote HTTP connections or suspicious file extensions (.dat), which are often used by adversaries to proxy the execution of malicious scripts or HTA files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
001
This query provides high-fidelity, post-exploitation hunting for CVE-2026-69730 by catching unauthorized child processes spawned from the Windows DNS Server engine (dns.exe).

Because dns.exe runs natively as NT AUTHORITY\SYSTEM and almost never executes external binaries during normal operations, filtering out known OS noise (conhost.exe and werfault.exe) flags potential RCE breakouts and privilege escalation with near-zero false positives.
avatar
Lightkun Yagami@lightkun_CrowdStriker
avatar
CrowdStrikers
1 month ago
20024
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy the Active Directory database file (ntds.dit) from the shadow copy. This pattern is commonly used by adversaries to perform offline credential dumping.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
25 days ago
005
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy the Active Directory database file (ntds.dit) from the shadow copy. This pattern is commonly used by adversaries to perform offline credential dumping.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
005
This rule monitors for the presence or execution of files matching a known set of SHA256 hashes associated with the 'DXSCAN' malware, utilizing both device file and process events.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
203
This rule monitors process creation, file system activity, and HTTP logs for indicators associated with the 'GHOST-VAULT' or 'GHOST-CRED' threat activity. It specifically triggers on files or paths containing 'GHOST-VAULT-', processes named 'ghost_' or containing 'ghost_' in the command line, and HTTP requests containing 'GHOST-CRED/3.0', 'GHOST-VAULT/', or 'GHOST/0day'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
303
Detects execution of potentially suspicious processes ('Launcher.exe' or 'GapiUpdate.exe') originating from ClickOnce-related processes ('dfsvc.exe' or 'rundll32.exe' with 'dfshim.dll'). ClickOnce is often abused to proxy execution of malicious code, allowing adversaries to execute applications from user-writable directories without administrative privileges.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
105
This rule detects the execution of NetSupport Manager related files, specifically 'client32.exe', or the presence of 'NetSupport' or 'Manager.zip' in command lines. NetSupport is a legitimate remote administration tool that is frequently abused by adversaries to maintain persistence and remote control over compromised hosts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
203
Detects the execution of PowerShell or pwsh with encoded command arguments containing a long base64 string, often used by attackers to hide malicious scripts from command-line logging and basic static analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
203
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
Page 258 of 1871