Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects the BlueMoon exploit kit's post-exploitation activity, specifically identifying when a Chromium-based browser process (chrome.exe or msedge.exe) initiates command-line tools such as cmd.exe, powershell.exe, or curl.exe to download and execute a secondary payload named 'msgbox.exe' within the user's temporary directory.
avatar
Thiru N@Iamthiru
avatar
Detections.ai Community
30 days ago
13013
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
003
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
003
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
000
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
000
The following analytic detects process injection into Notepad.exe using Sysmon EventCode 10. It identifies suspicious GrantedAccess requests (0x40 and 0x1fffff) to Notepad.exe, excluding common system paths like System32, Syswow64, and Program Files. This behavior is often associated with the SliverC2 framework by BishopFox. Monitoring this activity is crucial as it may indicate an initial payload attempting to execute malicious code within Notepad.exe. If confirmed malicious, this could allow attackers to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
000
The following analytic detects a process requesting duplicate-handle and query-limited-information access to winlogon.exe.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
000
The following analytic detects duplicate-handle access to known UAC-bypass binaries from a non-standard source path.
It leverages Sysmon EventCode 10, converts GrantedAccess from hexadecimal, and checks for PROCESS_DUP_HANDLE.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
000
The following analytic detects potential process injection attempts into executables that are commonly abused leveraging Sysmon EventCode 10.
It identifies Access Mask requests (0x40 and 0x1fffff) to processes such as notepad.exe, wordpad.exe and calc.exe, excluding common system paths like System32, Syswow64, and Program Files.
This activity was associated with the SliverC2 framework by BishopFox.
Monitoring this activity may indicate an initial payload attempting to execute malicious code.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
000
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
The following analytic detects the usage of wevtutil.exe with the "clear-log" parameter in order to clear the contents of logs.
Clearing the event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
000
The following analytic detects the wermgr.exe process creating an alternate stream in the temp directory. It leverages Sysmon EventID 15 to identify these actions.
This activity is significant because wermgr.exe is typically associated with error reporting, not file creation. Such activity is significant as it may indicate RoguePlanet malware, which creates an alternate stream in the temp directory to execute malicious code.
If confirmed malicious, this could lead to further malware infections, data exfiltration, or system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
000
Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
101
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
101
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects post-exploitation shell activity spawned from the IIS worker process (w3wp.exe), narrowed to command lines carrying encoded/obfuscated PowerShell flags, remote-download cradles, or basic recon/persistence commands (whoami, certutil, bitsadmin, schtasks, reg add). This reduces noise from benign w3wp.exe-initiated automation while retaining the behavioral pattern seen in the Telerik UI for ASP.NET AJAX unauthenticated RCE chain (webshell/in-memory DLL execution dropping to a shell).
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
004
Page 293 of 1871