Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream (ADS) from files. This stream is responsible for the 'Mark-of-the-Web' (MOTW) which triggers security warnings in Windows, including SmartScreen and Protected View. Adversaries use this technique to evade security controls on downloaded malicious files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
203
Detects a specific network handshake pattern characterized by the string 'REVERSE_PROXY|' within the first 16 bytes of an established TCP connection, consistent with the x47.c Fast-Flux botnet command and control (C2) communication protocol.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects network traffic consistent with the x47.c bot performing a SOCKS5 reverse-proxy handshake to a command-and-control (C2) server. The rule triggers on the specific 'REVERSE_PROXY|' string signature within established outbound TCP connections.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects high-frequency outbound network connections to known large language model (LLM) API providers (OpenAI, xAI, Anthropic) originating from a single endpoint within a short timeframe. This activity is indicative of potential API key theft, where an attacker uses a compromised legitimate key to exhaust credit quotas or exfiltrate data via unauthorized API calls, bypassing the intended application.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects instances where the suspicious binary 'x47_bot.exe' performs process injection or hollows a process, followed by an attempt to gain or elevate privileges (such as via UAC bypass, token manipulation, or privilege checking) on the same host within a 15-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects non-browser processes accessing sensitive browser-stored credential and cookie databases concurrently with access to Discord local storage, which is a common behavior of information-stealing malware (e.g., x47.c) to aggregate credentials for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
avatar
Arnold Chan@slaz
avatar
SlimKQL
18 days ago
308
Detects bursts of AI-paraphrased, brand/executive-impersonating email lures delivered to the inbox: clusters near-duplicate subject-line variants from the same sending domain within a 6-hour window, and requires a corroborating signal (authentication failure or a sender domain first seen within the last 14 days) plus an ESP allow-list exclusion to avoid flagging legitimate bulk/newsletter mail. Maps to T1683 (Generate Content) as the downstream-delivery proxy for AI-generated lure content.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
302
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
000
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
000
Detects instances where msbuild.exe is spawned from suspicious parent processes without valid project files and subsequently receives cross-process injection activity (such as CreateRemoteThread or WriteProcessMemory) within a short timeframe. This behavior is indicative of an adversary attempting to use MSBuild to proxy malicious code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
102
Detects instances where msbuild.exe is spawned from suspicious parent processes without valid project files and subsequently receives cross-process injection activity (such as CreateRemoteThread or WriteProcessMemory) within a short timeframe. This behavior is indicative of an adversary attempting to use MSBuild to proxy malicious code execution.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
002
Detects the creation or modification of registry run keys under HKCU or HKEY_USERS that use the value 'WindowsDefender' to point to an executable located within the AppData directory. This is a common technique used by malware to establish persistence while masquerading as a legitimate security component.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
002
Detects the creation or modification of registry run keys under HKCU or HKEY_USERS that use the value 'WindowsDefender' to point to an executable located within the AppData directory. This is a common technique used by malware to establish persistence while masquerading as a legitimate security component.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
002
Detects instances where msbuild.exe is spawned from suspicious parent processes without valid project files and subsequently receives cross-process injection activity (such as CreateRemoteThread or WriteProcessMemory) within a short timeframe. This behavior is indicative of an adversary attempting to use MSBuild to proxy malicious code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
002
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002