Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects DNS resolutions of known SpiceRAT command-and-control hostnames to multiple distinct C2 IP addresses within a 30-day window. This behavior is consistent with automated C2 infrastructure rotation or the use of multiple redundant IP addresses for persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects the creation of multiple or specific file locks that deviate from standard naming conventions, often associated with wiper malware attempting to overwrite files or fill disks by creating locking files as part of their destructive payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the spawning of suspicious processes like cmd, powershell, or certutil by the Exchange Server's web worker process (w3wp.exe), which is a common indicator of post-exploitation activity following an initial web vulnerability exploitation, such as ProxyLogon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects Python scripts containing natural-language comments that narrate attack rationale, reasoning, or step-by-step intent. This behavior is a diagnostic signature of scripts generated or operated by AI agents, which tend to document their own processes in plain text comments, unlike human-written malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects pre-encryption defensive measures employed by the Monkey ransomware C++ variant. This rule triggers on behaviors including Microsoft Defender exclusion management, disabling of AMSI or ETW components, manipulation of system security settings via registry, and attempts to clear PowerShell or command-line history to facilitate anti-forensic evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of processes related to the 'Toy Ghouls' bird-agent tool delivery, utilizing Evil-WinRM or WinRM-fs to execute commands remotely via the WinRM service (wsmprovhost.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the creation of a new local user account followed by its immediate addition to the Administrators or Remote Desktop Users groups, a common pattern observed in post-exploitation activities related to CVE-2019-0708 (BlueKeep) for achieving persistent administrative access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects suspicious child processes (cmd.exe, powershell.exe, java.exe) spawned by the PaperCut NG/MF server processes (pc-app.exe or java.exe), which is indicative of potential post-exploitation activity following remote code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of Mimikatz, a tool commonly used for credential harvesting from Windows memory, by monitoring for processes named 'mimikatz.exe' or the presence of specific Mimikatz command-line arguments used for dumping LSASS memory or performing pass-the-hash attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of native Windows administrative utilities (vssadmin, wmic, bcdedit, wbadmin) used by the Monkey ransomware C++ variant to delete volume shadow copies, clear the backup catalog, and disable system recovery boot policies. This activity is a characteristic precursor to data encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects potential exploitation attempts against Microsoft Exchange Server, specifically targeting the ECP (Exchange Control Panel) through VIEWSTATE parameter tampering related to CVE-2020-0688, and correlates this with suspicious behavior in the w3wp.exe process, such as unauthorized module loading (e.g., clr.dll, system.web.dll) and abnormal child process creation which may indicate the deployment of in-memory backdoors like GhostContainer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of offensive security tools like Evil-WinRM or winrm-fs, which are often used by threat actors for remote administration, lateral movement, or backdoor delivery via the Windows Remote Management (WinRM) protocol.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects unauthorized or potentially malicious file transfer activity within ScreenConnect sessions. The rule flags file transfers occurring on vulnerable versions of ScreenConnect (prior to 26.6.5), transfers that bypass user confirmation prompts, or instances where files are transferred and subsequently executed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule monitors for a collection of adversarial behaviors on Windows systems, including persistence mechanisms via scheduled tasks and registry run keys, tampering with security services (VSS, Windows Defender), credential harvesting attempts (LSASS memory), log and history clearing, and external network communication to known IP geolocation services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule monitors IT asset inventory data for instances of ConnectWise (ScreenConnect) software running outdated versions prior to 26.6.5, which are known to be vulnerable to CVE-2026-84869. Identifying these assets is critical for preventing potential exploitation of public-facing remote administration tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule monitors for additions to the 'Domain Admins' group (Event IDs 4728, 4732, 4756) that occur within 15 minutes of an authentication event (Event ID 4624) involving accounts associated with PaperCut software on a Domain Controller. This pattern is indicative of a potential follow-on action after a PaperCut exploitation incident, where an attacker leverages initial access to perform privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the deployment of the GhostContainer backdoor, which masquerades as an IIS server component loaded within w3wp.exe. The rule monitors for command-line arguments associated with web shells and known exploitation tools like reGeorg, indicating an attempt to maintain persistence following an Exchange server compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
102
Detects the use of Evil-WinRM or WinRM-fs command-line utilities combined with network connections over the WinRM ports (TCP 5985/5986). This activity is indicative of remote administrative tools being used for potential lateral movement or agent delivery, specifically observed in the context of the Toy Ghouls threat activity involving the Bird Agent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects unauthorized directory replication requests (DRSGetNCChanges or DRSReplicaSync) originating from a host that is not identified as a Domain Controller. This behavior is indicative of a DCSync attack, where an adversary impersonates a domain controller to extract credential hashes from the Active Directory database.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects suspicious process execution spawned by ScreenConnect client processes, which may indicate abuse of remote access sessions for arbitrary command execution. This includes both direct child processes of ScreenConnect client binaries and execution of binaries staged within known ScreenConnect working and temporary directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of Mimikatz or the use of specific Mimikatz command-line arguments intended to extract credentials from LSASS memory, a common technique for credential harvesting during post-exploitation activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Page 281 of 1871