Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation or writing of the specific log file '/logs/send_sms_apix.log' associated with the AnonyMousKIT Phishing-as-a-Service (PhaaS) platform. This file is typically used by the kit to record SMS billing or gateway activity during a phishing operation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects network connections (TLS SNI and HTTP requests) to domains associated with the AnonyMousKIT PhaaS (Phishing-as-a-Service) platform. It flags connections to known phishing backend domains and monitors for access to suspicious management dashboard paths commonly utilized by this threat actor for managing phishing orders and communications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects incoming emails that use 'Apple' or 'Find My' related strings in the sender display name while originating from common consumer email relay domains like Gmail or iCloud, which is indicative of a social engineering or phishing attempt attempting to impersonate Apple support.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects DNS queries for domains containing specific brand-related strings (such as government agencies or courier services) coupled with high-risk top-level domains (TLDs). This pattern is frequently used by adversaries to register infrastructure for phishing and social engineering campaigns by mimicking legitimate organizational presence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
102
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
502
Detects two distinct behaviors indicative of potential credential theft or lateral movement: DCSync-style Active Directory replication requests identified via Event ID 4662 with specific replication GUIDs, and high-volume SMB traffic originating from Domain Controllers or DC-adjacent hosts, which may indicate unauthorized data access or credential dumping activities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects successful OAuth 2.0 device authorization grant sign-ins using the 'Microsoft Authentication Broker' client. This pattern is commonly used in device-code phishing (GhostCode) to trick users into authorizing a malicious application, often bypassing multi-factor authentication (MFA) requirements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects the execution of shell interpreters (PowerShell, CMD, Bash, Zsh) with suspicious command-line arguments typically associated with malicious activity, such as encoded commands, hidden window styles, or network download requests, when initiated by common user-facing applications like web browsers or Windows Explorer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects HTML smuggling files identified as 'FlipBook' lures, commonly used in device-code phishing campaigns. These lures utilize client-side JavaScript for AES-GCM decryption, extensive comment-based obfuscation, and specific junk-padding techniques to bypass security controls and trick users into providing credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects network activity associated with the GhostCode phishing kit. It monitors for sequential calls to the harvester backend (geoip, get_code, and poll) from specific suspicious hostnames, indicating a likely interaction between a victim and a credential harvesting landing page.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects a suspicious multi-stage PowerShell execution pattern where an initial process, such as explorer.exe or common loaders, invokes PowerShell with obfuscated or download-related flags (e.g., -enc, IEX, DownloadString), followed immediately by a child PowerShell process performing further download or network operations within a short time window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
This rule monitors for processes that are digitally signed by 'Discord Inc.' or 'Lenovo' but executing from file paths that are not associated with legitimate installations of their software. This behavior is indicative of threat actors using stolen or compromised code-signing certificates to bypass security controls like SmartScreen or endpoint antivirus solutions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002