Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the loading of an unsigned or invalidly signed DLL from commonly abused user-writable directories (Temp, AppData, Public). This behavior is characteristic of DLL side-loading techniques, often used by threat actors like the Lazarus Group to execute malicious code via a legitimate, trusted application.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
Detects Microsoft Office applications (Winword/Excel) spawning PowerShell or MSHTA with base64-encoded command-line arguments, followed by subsequent persistence mechanisms such as creating scheduled tasks or modifying Registry Run keys. This behavior is indicative of APT38 (BlueNoroff) and similar campaigns delivering banking Trojans via malicious Office macros.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
This rule detects instances where Microsoft Word (winword.exe) or Microsoft Excel (excel.exe) initiate a PowerShell (powershell.exe) process containing command-line arguments typical of downloader stagers, such as 'IEX', 'DownloadString', or hidden execution flags. This behavior is a common indicator of macro-based delivery of malware, frequently observed in campaigns associated with FIN7/Carbanak and other threat actors utilizing Cobalt Strike or similar offensive frameworks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
102
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
002
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
102
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
8 days ago
202
Detects the creation of scheduled tasks (Windows), cron jobs (Linux), or systemd timers where the initiating process is a common scripting or runtime interpreter (e.g., Python, Node.js, PowerShell, Java). This activity is often indicative of persistence mechanisms being established by a compromised agent or script-based process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
Detects unauthorized creation or modification of AI agent system prompts, guardrails, or policy configuration files. This rule monitors for changes made by processes or users other than those identified as authorized CI/CD deployment agents or service accounts, helping to prevent unauthorized tampering with AI agent behavior or safety policies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Identifies suspicious processes performing beacon-like network communications with rare external destinations. The rule detects consistent hourly activity intervals and high connection counts to endpoints rarely contacted by other devices in the organization, serving as a heuristic for automated C2 beaconing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
Detects the use of legitimate data transfer utilities (s5cmd, rclone) configured to exfiltrate sensitive document types (.doc, .pdf, .sql, etc.) to S3-compatible cloud storage. The rule correlates this activity with recent access to files containing sensitive credentials or configuration data, a pattern observed in double-extortion campaigns.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
13 days ago
608
Detects execution of command-line tools commonly associated with system log clearing and secure file deletion. Specifically monitors for 'wevtutil' usage to clear logs, PowerShell commands to remove event log properties, and 'cipher /w' for permanent file data destruction.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
12 days ago
006
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
005
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
Detects the installation of known AI-powered coding assistant extensions (e.g., Copilot, Tabnine, Cursor) on a device, followed by significant source-code repository cloning or archival activity by Git within two hours. This pattern is potentially indicative of intellectual property theft or sensitive source code exfiltration facilitated by a newly introduced AI tool.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
306
Detects instances where a browser extension is installed, followed within a two-hour window by the browser process making network connections to generative AI service domains. This behavior is indicative of potential malicious browser extension activity, such as scraping or exfiltrating session/browsing data to third-party AI backend services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
206
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
005
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
103
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
SlimKQL
10 days ago
303
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
103
Detects a suspicious sequence where a process loads the .NET CLR (clr.dll or mscoree.dll) and shortly thereafter accesses specific low-prevalence file extensions (.raw or .pak) within high-risk directories (AppData/Local/Temp, ProgramData, or Users/Public). This behavior is characteristic of shellcode loaders (such as the WAV-shellcode loader) that decrypt and execute RAT payloads from obfuscated containers in memory. The rule intentionally excludes common desktop applications to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
103
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
203
Page 27 of 1866