Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the execution of PowerShell with a bypass execution policy that performs a download or web request to save content to a file in the user's temp directory, followed by the immediate execution of that file. This pattern is characteristic of multi-stage malware droppers or fileless attack techniques attempting to stage and execute malicious scripts from temporary locations.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
303
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
48172
This rule monitors for network communication with a specific known malicious IP address and URL path, as well as the execution or presence of associated malicious file hashes. Additionally, it flags emails involving specific indicators identified as potentially associated with malicious activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
002
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
avatar
Arnold Chan@slaz
avatar
SlimKQL
10 days ago
103
Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
17 days ago
11024
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
002
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
002
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
103
Detects HTTP GET requests for files with a .hta extension, utilizing a legacy Internet Explorer User-Agent string. This pattern is commonly associated with SideCopy threat group activities where mshta.exe is used to proxy the execution of remotely hosted malicious HTA files, often as part of an initial infection chain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
102
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
002
This rule detects potentially malicious PowerShell command execution originating from a Windows Remote Management (WinRM) process (wsmprovhost.exe). It monitors for child processes of wsmprovhost.exe launching powershell.exe or pwsh.exe combined with indicators of obfuscated command-line arguments, such as encoded commands, base64 strings, or common bypass/evasion parameters like IEX or -NoProfile.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
This rule detects potential exploitation attempts targeting the Splunk REST API (CVE-2026-20253) by monitoring for unauthenticated inbound requests to the /services/ path. It specifically looks for requests that lack the required Authorization or Cookie headers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
002
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
3023
Detects the execution of mshta.exe with arguments pointing to remote URLs or containing JavaScript. This behavior is commonly associated with phishing campaigns where attackers use fake CAPTCHA lures to trick users into executing malicious scripts via mshta.exe, often launched directly from Windows Explorer (e.g., from a downloaded file).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
003
This rule detects potential DLL side-loading attempts involving the legitimate Microsoft Defender binary 'mpextms.exe'. The rule triggers when 'mpextms.exe' is executed from a non-standard, user-writable directory (e.g., Temp, AppData, Downloads) and subsequently loads a specific 'endpointdlp.dll' from an equally suspicious location, indicating a potential attempt to masquerade malicious code execution behind a trusted process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
203
Detects rapid creation of numerous .lnk shortcut files on removable media volumes, specifically targeting filenames that mimic common installers (e.g., ChromeSetup, AnyDesk). This behavior is characteristic of worm-like malware attempting to use removable drives for persistence and lateral movement by masquerading as legitimate software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
203
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
102
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
102
This rule performs a point-in-time sweep for known Indicators of Compromise (IOCs) associated with the NeedyMantis threat actor group. The detection logic searches for specific file, process, and image-load SHA256 hashes, communication with a known C2 domain (tripswithengine.com), and the use of a hard-coded user-agent string (Firefox/21.0) across various telemetry sources within the last 30 days.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
303
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
102
Detects a behavioral fingerprint associated with the NeedyMantis group, characterized by the creation of a DLL and a identically-named, extensionless, encrypted archive file in the same directory within a short time window. This approach identifies the underlying packaging strategy rather than relying on static file names or known paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
203
Page 28 of 1866