Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the installation and execution of Cloudflare Tunnel (cloudflared.exe) as a Windows service. Adversaries may abuse this utility to create unauthorized persistent network tunnels, enabling covert remote access to the internal network. This rule correlates process creation events involving 'service install' or 'tunnel run' commands with Windows service installation events referencing the cloudflared binary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
104
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
104
Detects high-privileged Entra ID accounts successfully reaching the verification stage of the Self-Service Password Reset (SSPR) process. While SSPR is automatically enabled for administrative accounts, this activity is anomalous and potentially indicates an attacker focusing on discovered privileged accounts after performing broader enumeration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
Detects anomalous, high-volume account enumeration against the Microsoft Self-Service Password Reset (SSPR) endpoint from a single source IP. The rule identifies a pattern of mixed response codes, specifically interleaving '50034' (Account does not exist) with successful or other outcomes, which indicates the use of automated tools to validate the existence of corporate accounts via response differentiation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
001
Detects anomalous, high-volume account enumeration against the Microsoft Self-Service Password Reset (SSPR) endpoint from a single source IP. The rule identifies a pattern of mixed response codes, specifically interleaving '50034' (Account does not exist) with successful or other outcomes, which indicates the use of automated tools to validate the existence of corporate accounts via response differentiation.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
Detects anomalous Agentforce session activity where a user, via the General CRM subagent, queries Lead records followed shortly by an access request to Account records. This pattern is indicative of a potentially hijacked agent session attempting to pivot from lead review into unauthorized data access of broader customer information.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
001
This rule detects Salesforce Agentforce or similar AI-driven chat responses that contain external URLs with non-standard Top-Level Domains (TLDs). It identifies cases where the organization's redactor failed to strip a URL due to unexpected TLDs or unusual trailing termination characters (e.g., brackets) that are still rendered as clickable links in the interface. Such links may facilitate phishing, credential harvesting, or redirection to malicious sites.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
102
Detects the execution of Node.js or Python interpreters from user-writable directories (AppData/Local) that are executing specific script files. This pattern is indicative of potential malicious activity where legitimate scripting languages are leveraged to run unauthorized payloads dropped into the user profile.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
002
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
102
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
002
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
102
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
202
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
002
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
002
Detects the use of reg.exe to query the MachineGuid value from the Windows Registry (HKLM\SOFTWARE\Microsoft\Cryptography). This behavior is often associated with adversary reconnaissance, specifically host fingerprinting, to uniquely identify compromised machines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects unauthorized or non-standard processes attempting to access sensitive browser cookie storage files, which is a common technique used by credential-stealing malware to exfiltrate session data and bypass multi-factor authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the use of 7-Zip (7z.exe) to extract a file named drata.dat using command line arguments that indicate silent extraction from an encrypted or password-protected archive. This behavior is associated with the LegionLoader malware, which uses this technique to stage its payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
This rule detects suspicious PowerShell activity associated with the Lightlife RAT, specifically targeting Google Chrome's login data files to steal credentials and performing checks for the presence of cryptocurrency wallets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
703
This rule detects when a user or service account accesses or downloads a high volume of files from SharePoint or OneDrive that match sensitive keywords such as 'password', 'secret', 'credential', or specific file extensions like '.pem', '.pfx', and '.env'. This behavior is indicative of an attempt to harvest credentials, API keys, or configuration secrets from cloud storage repositories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102