Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects network connections to known remote tunneling and relay services (e.g., ngrok, Cloudflare Tunnel) initiated by commonly abused LOLBins or processes running from user-writable directories. This behavior is often indicative of an adversary establishing persistent remote access or egress channels for command-and-control communication.
avatar
F S@Fsdr
avatar
Detections.ai Community
28 days ago
4010
Detects potential DLL side-loading attempts involving GlobalProtect VPN components. The rule identifies the execution of GlobalProtect.exe with specific command-line arguments combined with the presence of suspicious versions of bcrypt.dll or WININET.dll within the same directory, which are characteristic of recent malicious activity involving modified DLL files targeting GlobalProtect environments.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
8024
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
202
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
002
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
206
Detects the execution of the Rubeus.exe utility with command-line arguments indicative of Kerberos-related credential harvesting and abuse, such as Kerberoasting, AS-REP Roasting, and Pass-the-Ticket attacks.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
006
This rule monitors for a multi-stage attack pattern involving two potential indicators: first, it identifies phishing emails containing a 'Google Docs' link combined with an attachment named 'API Logic Flaw'. Second, it detects browser activity involving the paste of JavaScript code or suspicious browser clipboard activity, which may indicate an attacker attempting to execute malicious scripts directly in the user's browser context.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
1 month ago
7016
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
102
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
002
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
002
Detects rapid AI agent state transitions (from 'think' to 'act') within Microsoft Edge processes, specifically identifying potential exploitation of the CVE-2026-55945 race condition vulnerability, which could be used to force the unauthorized execution of an injected prompt.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
002
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
30 days ago
5013
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
203
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
3017
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
104
Detects instances where a non-administrative user account creates two or more computer accounts within a 24-hour window. This behavior can be indicative of a compromised account attempting to add rogue machines to the domain for persistence or further lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
103
Detects unauthorized access or decryption attempts related to Group Policy Preferences (GPP) files stored in the SYSVOL share. Attackers often target these files to retrieve credentials stored in the 'cpassword' attribute, which can be decrypted using publicly known keys.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
103
Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
5016
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
6017
Detects potential credential dumping activities by monitoring process executions associated with known tools (Mimikatz, Procdump, Gsecdump) or commands that interact with the LSASS process memory to extract secrets.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
24 days ago
103
Page 291 of 1871