Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
002
Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
405
Detects execution of MeshAgent binaries when initiated by common scripting or application processes (e.g., java, sh, bash, python) or when displaying suspicious command-line patterns indicative of unauthorized remote access or download activity, particularly in environments like WebLogic or PeopleSoft.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
705
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
104
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
202
Detects activity associated with the MALFEX npm supply-chain campaign (also known as Overlord/movinlike). This rule performs a sweep for known malicious file hashes, suspicious process command lines, outbound network connections to malicious domains or IPs, and email communications from identified adversary-controlled accounts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
102
Detects activity associated with the MALFEX npm supply-chain campaign (also known as Overlord/movinlike). This rule performs a sweep for known malicious file hashes, suspicious process command lines, outbound network connections to malicious domains or IPs, and email communications from identified adversary-controlled accounts.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
102
Detects the installation or execution of known MALFEX malicious packages via npm or Node.js, which are used as entry points for polyglot or disguised payload delivery.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
002
This rule detects potential Remote Desktop Protocol (RDP) session hijacking or suspicious automation activity. It monitors for the execution of tscon.exe, a system utility used to control remote desktop sessions, or the usage of mstsc.exe (Remote Desktop Connection) over the standard RDP port 3389, which can be indicative of lateral movement or unauthorized access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
Detects attempts to dump the Local Security Authority Subsystem Service (LSASS) process memory for credential harvesting. The rule monitors for unauthorized process access requests (e.g., PROCESS_VM_READ), suspicious file creation of memory dumps in common writeable directories, and command-line execution of tools or techniques commonly associated with LSASS dumping (e.g., Mimikatz, procdump, or abusing comsvcs.dll).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
Detects the execution of script files with .js or .se extensions using wscript.exe or cscript.exe outside of standard system directories. This behavior is consistent with the More_eggs JScript backdoor, which has been utilized by the FIN6 threat group (also known as Skeleton Spider) to establish persistent backdoors for follow-on payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
Detects the use of PowerShell to download content from a remote URI and execute it using encoded commands or expression evaluation, a pattern commonly used by the FIN8 threat group (Syssphinx) to deploy the BADHATCH backdoor.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
Detects Microsoft Office applications (winword.exe or excel.exe) spawning shell processes (cmd.exe or powershell.exe). This behavior is commonly associated with malicious VBA macro execution in weaponized Office documents used for malware delivery, such as Dridex.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
Detects the creation of scheduled tasks that invoke rundll32.exe to execute code from suspicious, user-writable, or temporary file paths. This pattern is consistent with common persistence mechanisms employed by threat groups such as Wizard Spider (also known as Grim Spider, Gold Blackburn, and Periwinkle Tempest) to execute payloads like TrickBot or BazarLoader.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
Detects command-line indicators associated with destructive disk-wiping activity, specifically targeting disk structure corruption to render systems unbootable. This rule monitors for unauthorized use of the Windows 'diskpart' utility, direct raw physical drive access, and specific file system utility commands (fsutil) frequently observed in wipers attributed to APT44 (Sandworm).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
202
Detects the creation or modification of Windows Registry Run or RunOnce keys where the associated executable path is located in suspicious or non-standard directories (e.g., Temp, AppData, ProgramData). This behavior is characteristic of adversaries, such as APT28, attempting to maintain persistence by ensuring malicious code executes automatically upon user login.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
Detects the loading of an unsigned or invalidly signed DLL from commonly abused user-writable directories (Temp, AppData, Public). This behavior is characteristic of DLL side-loading techniques, often used by threat actors like the Lazarus Group to execute malicious code via a legitimate, trusted application.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
Detects Microsoft Office applications (Winword/Excel) spawning PowerShell or MSHTA with base64-encoded command-line arguments, followed by subsequent persistence mechanisms such as creating scheduled tasks or modifying Registry Run keys. This behavior is indicative of APT38 (BlueNoroff) and similar campaigns delivering banking Trojans via malicious Office macros.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
This rule detects instances where Microsoft Word (winword.exe) or Microsoft Excel (excel.exe) initiate a PowerShell (powershell.exe) process containing command-line arguments typical of downloader stagers, such as 'IEX', 'DownloadString', or hidden execution flags. This behavior is a common indicator of macro-based delivery of malware, frequently observed in campaigns associated with FIN7/Carbanak and other threat actors utilizing Cobalt Strike or similar offensive frameworks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
102
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
002
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
102
Page 26 of 1866