Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule hunts for indicators associated with the TrustSink technique, which involves using rogue External Authentication Methods (EAM) or malicious OIDC providers to bypass authentication or maintain persistence within a cloud environment. It monitors Azure AD sign-in and audit logs, alongside DNS and network events, for references to known malicious domains and URLs used for EAM-based attacks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
102
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
006
This rule monitors for successful sign-in events that follow a threshold of failed authentication attempts within a one-hour window, specifically flagging cases where the successful login originated from a new location or a previously unseen device, which is often indicative of successful brute force or password spraying attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
207
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
008
Detects indicators associated with the exploitation of CVE-2025-3248 in Langflow. The rule identifies anomalous web requests targeting the /api/v1/validate/code endpoint, subsequent suspicious process creation (base64 encoded payloads in Python/shell), and network communication with identified command and control (C2) or data exfiltration IP addresses. It also includes alerts for observed contact with known extortion email addresses.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
107
Detects indicators associated with the exploitation of CVE-2025-3248 in Langflow. The rule identifies anomalous web requests targeting the /api/v1/validate/code endpoint, subsequent suspicious process creation (base64 encoded payloads in Python/shell), and network communication with identified command and control (C2) or data exfiltration IP addresses. It also includes alerts for observed contact with known extortion email addresses.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
207
The following analytic detects the installation of the XMRIG coinminer driver on a system. It identifies the loading of the `WinRing0x64.sys` driver, commonly associated with XMRIG, by analyzing Sysmon EventCode 6 logs for specific signatures and image loads. This activity is significant because XMRIG is an open-source CPU miner frequently exploited by adversaries to mine cryptocurrency illicitly. If confirmed malicious, this activity could lead to unauthorized resource consumption, degraded system performance, and potential financial loss due to unauthorized cryptocurrency mining.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
14 days ago
103
The following analytic identifies user accounts experiencing more than 5 account lockouts within a 5-minute time window.
It leverages the 'Change' data model and groups account lockout events into 5-minute time buckets to identify a high frequency of lockouts associated with the same user and destination.
This activity may indicate password spraying, brute-force activity, or repeated authentication attempts using invalid or outdated credentials.
If confirmed malicious, this behavior may indicate an attempt to gain unauthorized access to user accounts and could precede further compromise or lateral movement within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
14 days ago
003
This rule detects network traffic containing specific API paths or hardcoded tokens known to be associated with suspicious or malicious activity, potentially indicating command-and-control (C2) communication or unauthorized interaction with a web service.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
20 days ago
8012
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
006
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
2012
Detects instances where the legitimate Windows Character Map utility (charmap.exe) is spawned by suspicious processes or PowerShell, and subsequently loads clr.dll. This behavior is indicative of potential DLL sideloading or process injection techniques used by malware to execute arbitrary code within a trusted system process context.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
5017
This rule monitors for indicators of compromise (IOCs) associated with the ShinyHunters threat actor, including specific malicious domains, IP addresses, and artifacts found in command lines or event data. It aggregates telemetry from network events, Entra ID sign-in logs, cloud application activity, email logs, process execution, and general device events to detect interaction with known malicious infrastructure or execution of threat-actor specific artifacts.
avatar
F S@Fsdr
avatar
Detections.ai Community
22 days ago
16023
This rule detects a password-spraying attack pattern directed at privileged or manager-titled accounts. It monitors for multiple failed sign-in attempts from a single source IP address against a large volume of distinct user accounts identified as managers or senior staff. The detection logic filters for low-frequency attempts per account, which is indicative of a distributed spray attack designed to evade account lockout thresholds while focusing on high-value targets.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects a password-spraying attack pattern directed at privileged or manager-titled accounts. It monitors for multiple failed sign-in attempts from a single source IP address against a large volume of distinct user accounts identified as managers or senior staff. The detection logic filters for low-frequency attempts per account, which is indicative of a distributed spray attack designed to evade account lockout thresholds while focusing on high-value targets.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects a password-spraying attack pattern directed at privileged or manager-titled accounts. It monitors for multiple failed sign-in attempts from a single source IP address against a large volume of distinct user accounts identified as managers or senior staff. The detection logic filters for low-frequency attempts per account, which is indicative of a distributed spray attack designed to evade account lockout thresholds while focusing on high-value targets.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects successful authentication events for accounts that have been dormant for at least 90 days, correlated with suspicious activity markers such as recent failed sign-in attempts, access from an unfamiliar geographic location or ASN, or a complete absence of historical sign-in activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects successful authentication events for accounts that have been dormant for at least 90 days, correlated with suspicious activity markers such as recent failed sign-in attempts, access from an unfamiliar geographic location or ASN, or a complete absence of historical sign-in activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000