Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
004
Detects anomalous, high-volume authentication failures originating from a single source IP address targeting multiple distinct internal devices within a short timeframe. This behavior is indicative of a password spraying or brute-force attack.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
005
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
005
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
avatar
Arnold Chan@slaz
avatar
Hunters
28 days ago
5010
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
106
Detects Mimikatz binary or in-memory module used for credential harvesting following PaperCut RCE exploitation
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
008
Detects the execution of netscan.exe, a common network scanning tool often used by adversaries to enumerate network resources, hosts, and services within a compromised environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule detects attempts to patch critical Windows functions used for security instrumentation, specifically 'AmsiScanBuffer' within 'amsi.dll' (often for bypassing AMSI) or 'EtwEventWrite' within 'ntdll.dll' (often for disabling ETW logging). This activity is highly indicative of defensive evasion techniques used by malware or malicious actors to hide their behavior from security tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects access to sensitive files (KeePass databases, SSH private keys, and VPN configurations) by processes other than their designated applications. This behavior indicates potential credential harvesting or configuration exfiltration by unauthorized processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects instances where a process has been elevated on a Windows system, as indicated by specific log messages containing 'Process is elevated' within the command line or image file name fields.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the creation of a scheduled task using 'schtasks.exe' configured to run as the SYSTEM account for a one-time execution. This behavior is often associated with persistence mechanisms or privilege escalation attempts where an adversary seeks to execute malicious code in a high-privileged context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule detects the use of 'taskkill.exe' to terminate critical services, including security software (MsMpEng.exe), database processes (sql.exe, oracle.exe, sqlservr.exe), and common user applications (outlook.exe, onedrive.exe). This behavior is characteristic of the DragonForce ransomware, which disables protective services and applications before encryption to minimize interference and ensure successful file locking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects unauthorized modification of the registry path 'HKCU\Software\Classes\ms-settings\Shell\Open\command'. This registry key is commonly hijacked by the 'fodhelper.exe' UAC bypass technique, where an attacker writes a malicious command to be executed with elevated privileges when the OS triggers the ms-settings protocol handler.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the CRPx0 ransomware technique of unhooking ntdll.dll in memory. This is achieved by reading the ntdll.dll file from disk and overwriting the in-memory .text section with a clean, unhooked version to bypass EDR monitoring and execute direct syscalls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects modifications to the Windows RunMRU registry key that include suspicious strings such as 'powershell', 'curl', or long base64-encoded sequences. This behavior is indicative of the 'ClickFix' technique, where users are socially engineered to paste and execute malicious commands directly into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of PowerShell encoded commands that result in the installation of known remote monitoring and management (RMM) software. This pattern is indicative of attackers, specifically those associated with Ransom Busters or similar affiliates, establishing persistent remote access to compromised systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the creation of a Windows scheduled task configured to execute as the SYSTEM account using a one-time execution trigger. This combination is frequently used by adversaries for post-exploitation activities, such as lateral movement or persistence, as it allows for a single, immediate execution of a malicious payload with high-level privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of the SoftPerfect Network Scanner tool (netscan.exe), which is often used by adversaries for reconnaissance to identify active hosts, open ports, and services within a network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the termination of critical processes, including security software (MsMpEng.exe), database services (sql.exe, oracle.exe, sqlservr.exe), and office productivity applications (excel.exe, outlook.exe, winword.exe). The sudden termination of these processes can indicate unauthorized attempts to disable security controls, disrupt database operations, or interfere with end-user activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule monitors Microsoft Teams communications for keywords related to passkey or Single Sign-On (SSO) configuration, which are common themes in social engineering and credential harvesting attacks. It correlates these messages with Windows logon events (Event ID 4624) for the sender to identify potentially compromised accounts or active phishing attempts originating from within the environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects DNS resolution requests for graph.microsoft.com initiated by a python interpreter (python.exe, python3.exe, or pythonw.exe). This activity may indicate a script or custom tool communicating with Microsoft Graph API, which is frequently used for data collection, exfiltration, or cloud service interaction in adversarial campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Page 271 of 1871