Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
002
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
002
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
002
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
002
Detects instances where the process 'GRrte.exe' forcefully terminates 'iediagcmd.exe' using taskkill.exe. This activity is indicative of an attempt to disable or impair specific security diagnostic tools or EDR-related components on the host.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
101
This rule detects potential credential dumping attempts targeting the Local Security Authority Subsystem Service (LSASS) process. It identifies suspicious file execution based on a blocklist of known credential dumping utility hashes, unauthorized OpenProcess calls to lsass.exe with specific access rights, and the creation of process memory dump files (e.g., .dmp, .dump) correlated with an lsass.exe access event.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
102
This rule detects potential credential dumping attempts targeting the Local Security Authority Subsystem Service (LSASS) process. It identifies suspicious file execution based on a blocklist of known credential dumping utility hashes, unauthorized OpenProcess calls to lsass.exe with specific access rights, and the creation of process memory dump files (e.g., .dmp, .dump) correlated with an lsass.exe access event.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
002
This rule detects potential DLL side-loading activity by identifying when known malicious file hashes are loaded by a specific set of executable files that are commonly abused for side-loading, or when these executables are executed from locations outside of their standard, verified installation directories.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
002
Detects network activity or command line parameters initiated by the Jarte text processor (Jarte.exe or GRrte.exe) originating from a JartePortable directory, indicating potential C2 activity involving the domain 'castanaksa.com' or the IP address '192.64.119.189'.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
001
This rule detects the opening of a specific PDF file named 'OIC_Invitation_General_Official.pdf' by Adobe Acrobat. The detection logic triggers either when Acrobat processes this file or when the file itself is identified on the system. This pattern has been associated with the delivery of the PlugX remote access tool, often used in targeted spearphishing campaigns.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
001
This rule detects the creation or modification of registry run keys associated with the JartePortable application. The detection logic looks for persistence mechanisms that point to executable paths in public directories or specific registry value data associated with known PlugX malware activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
201
Detects Adobe Acrobat (Acrobat.exe) launched by a suspicious parent process (GRrte.exe) while opening a specific PDF document from the user's temporary directory. This pattern is indicative of a potential malicious document lure often associated with malware delivery.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
001
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
003
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
avatar
Arnold Chan@slaz
avatar
SlimKQL
24 days ago
003
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
103
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
003
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
003
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
003
This rule detects unauthorized processes modifying the 'Secure Preferences' configuration file in Google Chrome or Microsoft Edge browser data directories. This activity often indicates an attempt by malicious software to hijack browser settings, such as forcing extensions or modifying security policies, which is a common precursor to credential theft or persistent malicious access.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
003
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
003
Page 290 of 1871