Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
105
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
001
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
001
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
101
Detects network and DNS activity associated with the SideCopy threat group, specifically monitoring for connections to known C2 domains, C2 IP addresses, or the usage of port 5863 typically associated with the ReverseRAT backdoor.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
000
Detects suspicious execution of ServiceModelReg.exe, either by referencing a specific known malicious file path ('purosangue.tx') or when launched by an unexpected parent process. This activity is indicative of potential COM elevation moniker abuse or process hollowing techniques often used in post-exploitation scenarios.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
This rule detects activities related to the loading or registration of the 'NvFsFilter' driver (nvfsflt64.sys). It monitors for command-line attempts to interact with services (using sc.exe, reg.exe, or services.exe), registry modifications involving the NvFsFilter service, and the actual loading of the nvfsflt64.sys file. This is intended to identify potential persistence mechanisms or the deployment of potentially unauthorized or malicious drivers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the deletion of registry keys or values associated with Google Chrome's extension settings preferences. This activity may indicate an attempt to disable installed extensions or tamper with browser security configurations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects a malicious browser helper DLL (Rapuncel) that attempts to inject into web browsers like Chrome and Edge. The rule identifies code that interacts with the browser's Elevation Service 'DecryptData' method, a technique used to bypass app-bound encryption, potentially to extract sensitive information like stored credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects evidence of the Alinubx.sys kernel driver being loaded or interacted with via its device interface using a specific IOCTL (0x222024). This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, effectively bypassing Windows Protected Process Light (PPL) protections.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects anomalous behavior within a Chrome renderer process involving the acquisition of SeDebugPrivilege, preceded by ALPC, WNF, or reflective DLL loading activities. This pattern is indicative of the BlueMoon (CVE-2026-85880) kernel privilege escalation exploit chain, where a compromised low-integrity renderer leverages kernel vulnerabilities to gain elevated privileges.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
7016
This rule detects the execution of 'vsdbg.exe', the Visual Studio Remote Debugger, from non-standard directories (e.g., Downloads, AppData, Temp, ProgramData) or in conjunction with the creation of 'vsdbg.dll' files. Adversaries may utilize this debugger for remote code execution or to bypass security controls by masquerading as a legitimate development tool.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
This rule detects successful logon events (Event ID 4624) or special logon events (Event ID 4648) with specific logon types (7: NetworkCleartext, 8: NewCredentials, 9: Network, 11: CachedInteractive) that occur within 24 hours of a user registration event on the same host. This pattern may indicate suspicious account usage shortly after account creation or registration on a device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the execution of known Living-off-the-Land Binaries (LOLBins) such as finger.exe or curl.exe that are spawned by common Windows processes like explorer.exe or RuntimeBroker.exe. This behavior is often associated with adversaries attempting to download malicious payloads or stage tools within the environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
This rule detects the potential use of parent process spoofing (PPID spoofing) where a PowerShell process is spawned with 'explorer.exe' as its parent. This technique, often executed via the 'PROC_THREAD_ATTRIBUTE_PARENT_PROCESS' attribute in a 'CreateProcessW' call, is used by adversaries to mask the true origin of the PowerShell process and evade behavioral detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects post-exploitation shell activity spawned from the IIS worker process (w3wp.exe), narrowed to command lines carrying encoded/obfuscated PowerShell flags, remote-download cradles, or basic recon/persistence commands (whoami, certutil, bitsadmin, schtasks, reg add). This reduces noise from benign w3wp.exe-initiated automation while retaining the behavioral pattern seen in the Telerik UI for ASP.NET AJAX unauthenticated RCE chain (webshell/in-memory DLL execution dropping to a shell).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
305
Detects unauthorized access attempts to browser credential files (such as Login Data, key4.db, and cookies) by non-browser processes. This behavior is indicative of the Rapuncel infostealer, which harvests stored browser credentials after attempting to disable or bypass security solutions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects unauthorized access attempts to browser credential files (such as Login Data, key4.db, and cookies) by non-browser processes. This behavior is indicative of the Rapuncel infostealer, which harvests stored browser credentials after attempting to disable or bypass security solutions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the ClickFix social-engineering pattern where a user is tricked into pasting and executing a command, typically via the Windows Run dialog (explorer.exe), that triggers the command shell (cmd.exe or powershell.exe) to utilize finger.exe or curl.exe for downloading and staging malicious payloads like CastleRAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects unauthorized access to critical browser files such as cookies, login data, and local state files. These files contain sensitive information such as authentication cookies and stored credentials, which are primary targets for infostealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
101
Detects the execution of curl.exe by various script interpreters (cmd.exe, powershell.exe, wscript.exe, mshta.exe) or Windows Explorer. This pattern is commonly used by adversaries to download malicious payloads or intermediate loaders as part of an attack chain, such as deploying CastleLoader/CastleRAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Page 276 of 1871