Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects potential malicious activity by monitoring for known malicious file hashes (MD5) across file and process events, and correlating them with known Command and Control (C2) infrastructure communication patterns, including specific IP addresses and URI paths.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule detects potential malicious activity by monitoring for known malicious file hashes (MD5) across file and process events, and correlating them with known Command and Control (C2) infrastructure communication patterns, including specific IP addresses and URI paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
This rule detects potential malicious activity by monitoring for known malicious file hashes (MD5) across file and process events, and correlating them with known Command and Control (C2) infrastructure communication patterns, including specific IP addresses and URI paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects the execution of AutoIt-related processes from temporary directories that are attempting to load or execute suspicious .ini configuration files or specifically named executables, which is a common delivery mechanism for malware such as AsyncRAT.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
25 days ago
104
This rule detects potential persistence mechanisms where a suspicious batch file (.bat) is placed within the Windows Startup folder and subsequently executed using command-line arguments that include specific file extensions like .exe and .ini. This behavior is indicative of malware, such as remote access trojans (RATs), attempting to maintain persistence upon system reboot.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
25 days ago
204
Detects process execution patterns consistent with the "ClickFix" social
engineering technique, where a user is lured (via a fake CAPTCHA, browser
error, or "verify you are human" page) into pressing Win+R, pasting a
pre-copied malicious command, and pressing Enter. This typically launches
PowerShell, mshta, cmd, or curl directly as a child of explorer.exe with
no legitimate parent chain (no browser, no script host), often with
obfuscated or encoded command lines, and frequently reaching out to
attacker infrastructure.
avatar
Myat Min Khant@blitzkri3g
avatar
Detections.ai Community
18 days ago
000
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
003
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
003
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
003
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
003
Detects outbound network connections to known command-and-control IP addresses associated with the SpiceRAT malware family. The rule monitors DeviceNetworkEvents for successful connections or connection attempts over ports 80 and 443.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
22 days ago
002
Page 280 of 1871