Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
103
Detects anomalous sign-in patterns indicative of real-time MFA relay attacks, where a user principal authenticates successfully from multiple distinct IP addresses and geographical locations within a short time window (15 minutes), suggesting the active interception of credentials and MFA challenges by a Phishing-as-a-Service platform.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects anomalous sign-in patterns indicative of real-time MFA relay attacks, where a user principal authenticates successfully from multiple distinct IP addresses and geographical locations within a short time window (15 minutes), suggesting the active interception of credentials and MFA challenges by a Phishing-as-a-Service platform.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
201
Detects anomalous sign-in patterns indicative of real-time MFA relay attacks, where a user principal authenticates successfully from multiple distinct IP addresses and geographical locations within a short time window (15 minutes), suggesting the active interception of credentials and MFA challenges by a Phishing-as-a-Service platform.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
101
This rule detects a suspicious monetization pattern where a user account experiences a high-risk sign-in event, followed shortly (within 2 hours) by the creation or modification of inbox rules. This pattern is often indicative of account compromise, where an adversary configures mailbox rules (e.g., forwarding or redirection) to facilitate data exfiltration or financial fraud.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
101
This rule detects a suspicious monetization pattern where a user account experiences a high-risk sign-in event, followed shortly (within 2 hours) by the creation or modification of inbox rules. This pattern is often indicative of account compromise, where an adversary configures mailbox rules (e.g., forwarding or redirection) to facilitate data exfiltration or financial fraud.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects a specific concealment behavior attributed to the 'com.corp.mdm' Android implant. The rule monitors for a sequence of events where the application disables its own launcher (main activity) to hide from the app drawer, immediately followed by the initiation of a foreground service that masquerades as a system notification ('Android System' title with 'System service running.' text).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects unauthorized or suspicious use of USSD codes by the corporate MDM agent to modify call-forwarding settings. This activity is indicative of a compromise where an attacker uses an MDM-controlled device to intercept calls or divert communications.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects cleartext HTTP POST requests to specific URI endpoints (/api/v1/devices/register or /api/v1/devices/heartbeat) known to be used by the Corp_MDM Android spyware for C2 communication, registration, or heartbeat signals.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects an Android device registration attempt to a known malicious C2 IP address using parameters characteristic of a mobile device management (MDM) implant. The rule looks for a POST request to a specific registration endpoint containing device identifiers like deviceId, manufacturer, model, and osVersion.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects an Android device registration attempt to a known malicious C2 IP address using parameters characteristic of a mobile device management (MDM) implant. The rule looks for a POST request to a specific registration endpoint containing device identifiers like deviceId, manufacturer, model, and osVersion.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects an Android device registration attempt to a known malicious C2 IP address using parameters characteristic of a mobile device management (MDM) implant. The rule looks for a POST request to a specific registration endpoint containing device identifiers like deviceId, manufacturer, model, and osVersion.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects HTTP beaconing and command-and-control (C2) communication patterns consistent with the 'Corp_MDM' Android spyware, specifically heartbeat check-ins, command polling, and result reporting to a known malicious C2 IP address.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects HTTP beaconing and command-and-control (C2) communication patterns consistent with the 'Corp_MDM' Android spyware, specifically heartbeat check-ins, command polling, and result reporting to a known malicious C2 IP address.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects HTTP beaconing and command-and-control (C2) communication patterns consistent with the 'Corp_MDM' Android spyware, specifically heartbeat check-ins, command polling, and result reporting to a known malicious C2 IP address.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects HTTP beaconing and command-and-control (C2) communication patterns consistent with the 'Corp_MDM' Android spyware, specifically heartbeat check-ins, command polling, and result reporting to a known malicious C2 IP address.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects the presence of known Vidar infostealer samples by matching file hashes against a list of identified malicious artifacts. The rule monitors for file creation events, process execution (both as the primary process and as an initiating process), and network activity originating from these known malicious files.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
103
Detects the presence of known Vidar infostealer samples by matching file hashes against a list of identified malicious artifacts. The rule monitors for file creation events, process execution (both as the primary process and as an initiating process), and network activity originating from these known malicious files.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
14 days ago
203
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
203