Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates execution of common command-line utilities or scripting interpreters, such as cmd.exe, powershell.exe, or certutil.exe. This behavior is highly atypical for web servers and is often indicative of exploitation attempts or post-exploitation activities following an initial compromise of a web application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule detects potential web shell activity on Microsoft Exchange servers by identifying suspicious processes (like cmd.exe, powershell.exe) spawned by w3wp.exe (IIS worker process) that are associated with the creation or modification of common web shell file extensions (.aspx, .ashx, .asax) within critical Exchange server directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects high-frequency execution of Python interpreter processes within a short timeframe (40+ distinct command lines in 15 minutes). This behavioral pattern is indicative of automated or autonomous agent-driven payload delivery and execution, as seen in JADEPUFFER and ENCFORGE campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule detects processes accessing or files being interacted with that are known to contain sensitive information, including API keys, credential files, database configurations, and cryptocurrency wallets. It monitors command-line activity for utilities like python, bash, and grep interacting with sensitive strings, and tracks file system access to sensitive paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule detects attempts to exploit Apache Nacos vulnerabilities, including authentication bypass and unauthorized administrative account creation. It monitors process executions of common tools (like curl and java) and network connections targeting known Nacos service ports (8848, 9848) containing indicators of exploit patterns such as login bypass endpoints or SQL injection sequences targeting the user table.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of ScreenConnect client processes initiating rapid outbound network connections to multiple distinct devices within a short timeframe (1 hour). This behavior is often indicative of unauthorized lateral movement, automated discovery, or mass-deployment of remote access sessions using legitimate administrative software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects a sequence of activity involving the use of the MySQL 'AES_ENCRYPT' function followed by a 'DROP TABLE', 'DROP SCHEMA', or 'DROP DATABASE' command on the same host within a 30-minute window. This behavior is consistent with extortion tactics, such as the JADEPUFFER campaign, where attackers encrypt sensitive database records and delete the original tables to compel ransom payments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects potential DCSync attacks by monitoring Windows Security Event ID 4662 for specific Directory Service Replication GUIDs. The rule identifies attempts by unauthorized principals (not domain controllers) to request replication data from the Active Directory domain controller, which is a key indicator of credential harvesting using tools like Mimikatz.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects potential web shell or malicious DLL deployment into Microsoft Exchange or IIS directories by the IIS worker process (w3wp.exe), as well as suspicious child process execution (such as command-line shells or credential discovery tools) spawned directly from IIS worker processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
102
Detects the ScreenConnect remote access binary spawning suspicious child processes often associated with lateral movement, system reconnaissance, or anti-forensics activity (such as deleting shadow copies, modifying boot configuration, or using administrative tools for remote command execution). This behavior is highly indicative of an adversary abusing legitimate RMM software to execute post-exploitation commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the presence of natural-language self-narration in code comments within Python or SQL scripts. This pattern is indicative of LLM-driven agentic execution, where automated agents narrate their own malicious actions, such as enumeration, data exfiltration, or database manipulation, as observed in the JADEPUFFER campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of 'SimpleService.exe' when the binary is located within a restricted subdirectory associated with JWrapper-Remote Access. This pattern may indicate the execution of unauthorized or restricted remote access tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the addition of a user to the 'Domain Admins' group using common administrative command-line tools such as net group, Add-ADGroupMember, dsadd, or net localgroup. This serves as a proxy indicator for potential privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of MySQL process command lines that simultaneously contain the strings 'AES_ENCRYPT' and 'UPDATE'. This pattern often indicates attempts to manipulate data within the database via SQL injection or unauthorized database modification.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the ENCFORGE locker malware, associated with the JADEPUFFER campaign, which specifically targets AI/ML-related files such as model checkpoints, vector databases, and training data for the purpose of malicious encryption or destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects instances where a Langflow process spawns a Python process using command-line arguments involving base64 decoding or character-based execution, which is often indicative of malicious code injection or shellcode execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects file creation events initiated by ScreenConnect (ConnectWise Control) client processes. ScreenConnect is a legitimate remote support and RMM tool often leveraged by adversaries for remote access or as a secondary persistence mechanism. Monitoring file creation by these processes may indicate the installation of additional tools, scripts, or malware via a remote support session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of native Windows utilities (vssadmin, wbadmin, bcdedit, wmic) to delete volume shadow copies, backup catalogs, or disable system recovery features. This behavior is a common precursor to or component of ransomware encryption operations intended to prevent system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of common command-line or scripting interpreters (cmd, powershell, cscript, etc.) spawned by the ScreenConnect remote administration client. This is a common pattern used by attackers leveraging legitimate remote access tools for post-exploitation activities and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
102
Detects the presence of known malicious RubyGems package names and Cross-Site Scripting (XSS) payloads within process commands, file paths, or network URLs, indicative of an attempt to target repository registries or administrative interfaces with supply chain injection attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
103
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
309
Page 279 of 1871