Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the presence or execution of a specific file hash associated with a known malicious campaign (KREMLIN/REF9334) that leverages a signed SentinelOne binary. This indicates potential abuse of trusted code-signing to bypass security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
103
Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
004
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
004
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
204
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
004
Detects PowerShell processes using the .NET System.IO.File methods (SetLastWriteTime, SetCreationTime, SetLastAccessTime) to modify file timestamps, a common anti-forensic technique to obfuscate file creation or modification times.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
000
Detects PowerShell processes using the .NET System.IO.File methods (SetLastWriteTime, SetCreationTime, SetLastAccessTime) to modify file timestamps, a common anti-forensic technique to obfuscate file creation or modification times.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
000
Detects PowerShell processes using the .NET System.IO.File methods (SetLastWriteTime, SetCreationTime, SetLastAccessTime) to modify file timestamps, a common anti-forensic technique to obfuscate file creation or modification times.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
000
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
000
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
000
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
003
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
003
Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
000
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
003
This rule detects HTTP requests directed at Microsoft Exchange Outlook Web Access (OWA) that contain suspicious 'fakePath' and 'fakePageName' parameters in the URI. These parameters are indicators of the 'GhostContainer' malware attempting to establish a socket forwarding proxy through the web server to facilitate command and control communications.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
003
Detects anomalous MS_T120 channel binding and MCS handshake patterns characteristic of the BlueKeep (CVE-2019-0708) remote code execution vulnerability in Microsoft RDP services.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
003
Detects anomalous MS_T120 channel binding and MCS handshake patterns characteristic of the BlueKeep (CVE-2019-0708) remote code execution vulnerability in Microsoft RDP services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
003
Detection rules identifying malformed RDP MCS Connect Initial PDUs and unusual service crashes following RDP connection attempts, both indicative of exploitation attempts against the CVE-2019-0708 (BlueKeep) vulnerability.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
003
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
105
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
005
Page 275 of 1871