Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the deletion of .zip files within the Public directory by VBScript or JScript interpreters (wscript.exe or cscript.exe). This pattern is often indicative of a malicious dropper or downloader that extracts a payload from a staged archive and subsequently removes the evidence to hinder analysis and forensics.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of a .vbs script file that contains '.pdf' in its filename, followed within 5 minutes by the execution of a WMI query via wscript.exe. This behavior is indicative of a malicious VBScript dropper attempting to perform system discovery using WMI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects Azure AD sign-in events where Multi-Factor Authentication (MFA) was reportedly satisfied by an External Authentication Method (EAM) claim without evidence of a traditional secondary authentication challenge. This behavior is indicative of a 'TrustSink' technique where a rogue or compromised OIDC provider injects a spoofed assertion of MFA success into the authentication token.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
202
Detects the execution of Windows Script Host (wscript.exe/cscript.exe) loading WMI-related modules (wbemprox.dll, wbemcomn.dll, etc.). This pattern is often indicative of scripts attempting to query WMI for system information, environment configuration, or locale data, which is a common reconnaissance technique used by malware to identify the victim environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of a .vbs script file that contains '.pdf' in its filename, followed within 5 minutes by the execution of a WMI query via wscript.exe. This behavior is indicative of a malicious VBScript dropper attempting to perform system discovery using WMI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where wscript.exe deletes a .zip archive from within the C:\Users\Public\ directory structure. This activity is frequently associated with VBScript droppers performing anti-forensic cleanup by removing staged payloads after extraction but prior to execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects when a user account assigned to high-privileged roles (Global Administrator or Authentication Policy Administrator) performs sensitive operations such as application registration, service principal creation, or modifications to authentication policies within a short timeframe (4 hours) of a successful sign-in. This activity is often associated with the initial setup phases of MFA bypass or persistence techniques in Entra ID.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
202
This rule detects the execution of script files (such as .vbs, .vbe, .js, .jse) via wscript.exe when the file name uses a double-extension technique (e.g., .pdf.vbs) to masquerade as a benign PDF document. These files are typically found in temporary or user-download directories, indicating potential malicious activity initiated by downloaded attachments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of wscript.exe or cscript.exe with a command line containing a .vbs file, occurring within a 5-minute window of the creation of a file named 'notepad++.exe' or 'readme.txt' within a sub-directory of 'C:\Users\Public\'. This behavior is indicative of a potential multi-stage execution where a script is used to drop or interact with files in public-accessible folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects potential malicious VBScript behavior where the script queries system language settings via WMI and subsequently launches a decoy message box commonly associated with initial-stage malware loaders or droppers to deceive users before initiating a payload download.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule identifies sign-in events using an External Authentication Method (EAM) that occur within the 2-day cache window immediately following a certificate or key credential update for an application or service principal in Entra ID. This detection highlights a timeframe where an attacker potentially possessing a compromised old signing key could use it to forge tokens before the Entra cache refreshes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects outbound network traffic (TLS SNI and HTTP requests) directed to the Telegram Bot API endpoint. This behavior is often associated with malware using Telegram as a command-and-control (C2) channel or for the exfiltration of stolen data, credentials, or sensitive information.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects potential phishing emails themed around financial documents or shared files that contain URLs associated with device-code authorization phishing lures, such as ARToken PhaaS, or links hosted on workers.dev platforms commonly used for such activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects potential theft and reuse of session or refresh tokens for Microsoft 365 services (Exchange/SharePoint) by identifying multiple authentication events for the same user account from different geographic locations and IP addresses within a short timeframe, specifically when no new MFA challenge was performed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects HTTP requests containing potential session, handoff, or access tokens within the URI pattern commonly associated with ORAX Adversary-in-the-Middle (AiTM) phishing infrastructure. The rule specifically targets requests routed to wildcard subdomains that mimic legitimate deployment or service endpoints, indicating an attempt to harvest authentication tokens from victims.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects potential abuse of the Microsoft Graph API by correlating device-code authentication events with subsequent high-volume activity, such as mail or file enumeration, from the same account within a short window. This pattern is indicative of ARToken-style token proxying, where an attacker intercepts an OAuth device-code token to gain unauthorized access to an user's resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects the creation of suspicious O365 inbox rules designed to hide (via mark-as-read, move, or delete actions) or forward/redirect email messages containing keywords associated with financial transactions such as payment, wire, or invoice. This behavior is indicative of post-compromise activity, specifically targeted at invoice fraud or email thread hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects phishing emails that use common voicemail notification subject lines combined with Mailchimp click-tracking or redirect infrastructure. This combination is often used to bypass traditional email gateway filters by utilizing legitimate marketing service domains to obfuscate final malicious destinations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects phishing emails that impersonate invoice-related correspondence, containing SharePoint links and a .url shortcut file attachment, a common technique for credential harvesting or malware delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects network indicators associated with the ORAX Phishing-as-a-Service (PhaaS) platform. This includes patterns for emoji-matching CAPTCHAs, spoofed Cloudflare security pages, specific wildcard subdomain DNS queries, and the use of anti-analysis gate sequences to prevent sandbox inspection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects network activity associated with a phishing campaign leveraging Cloudflare Workers, identified as 'ARToken'. The rules monitor for specific TLS SNI patterns, HTTP Host headers, and subsequent C2-like behavior involving device code authentication flows (api/device/start and api/device/poll) hosted on 'workers.dev'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002