Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects the creation of executable files (.exe, .dll, .ps1) in common writable and potentially transient directories such as Temp, AppData, ProgramData, or Users\Public. It further correlates these file events with process creation events using the file hash to identify instances where such files are subsequently executed.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
24 days ago
203
Detects the execution of wmic.exe, powershell.exe, or pwsh.exe with command-line arguments related to querying antivirus products or security centers (e.g., AntiVirusProduct, SecurityCenter2). The rule focuses on executions originating from non-standard system paths (e.g., Temp, Users, AppData) or processes that lack a valid code signing signature, which is often indicative of reconnaissance by malicious actors.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
103
This rule identifies the execution of specific binaries (Kingsoft Office suite and Onkey/Tendyron components) from suspicious or uncommon directories such as temporary folders, user downloads, or public directories, which may indicate the staging and execution of malicious payloads masquerading as legitimate software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
203
Detects several potentially malicious activities related to Active Directory Certificate Services (AD CS). This includes high volumes of failed requests (potential enumeration), requests for sensitive templates (privilege escalation), and potential impersonation attempts using Subject Alternative Names (SANs). These activities are associated with AD CS abuse techniques.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
107
Detects instances where the Windows Remote Management host process (wsmprovhost.exe) is associated with the execution of specific suspicious files (config.toml, cplsupport.exe, or wtass.exe) within a short time window. This activity often indicates post-exploitation behavior or remote execution of secondary tools using WinRM.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
207
Detects msiexec.exe executing from the Temp directory with suspicious command-line arguments (such as hidden windows) and spawning child processes like cmd.exe, tasklist.exe, or taskkill.exe. This behavior is often indicative of malicious installation scripts attempting to perform discovery or terminate security processes while remaining stealthy.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
007
This rule monitors for network connections to known command-and-control (C2) IP addresses and the execution or presence of files matching known hashes associated with the 'PhantomC2' threat group or malware family. It correlates data from DeviceNetworkEvents, DeviceFileEvents, and DeviceProcessEvents to identify potential compromise.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
404
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
004
Detects network communication with identified C2 infrastructure associated with VectraRAT, Amadey, and ClickFix campaigns, as well as the presence of a specific 'callback.json' artifact in temporary directories, which is commonly used for C2 address overrides.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
204
Detects network communication with identified C2 infrastructure associated with VectraRAT, Amadey, and ClickFix campaigns, as well as the presence of a specific 'callback.json' artifact in temporary directories, which is commonly used for C2 address overrides.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
204
Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
104
Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
204
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
000
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
000
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects the BlueMoon exploit kit's post-exploitation activity, specifically identifying when a Chromium-based browser process (chrome.exe or msedge.exe) initiates command-line tools such as cmd.exe, powershell.exe, or curl.exe to download and execute a secondary payload named 'msgbox.exe' within the user's temporary directory.
avatar
Thiru N@Iamthiru
avatar
Detections.ai Community
30 days ago
13013
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
003
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
003
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
000
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
000
Page 292 of 1871