Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects sign-in activity where an attacker or user fails a phishing-resistant MFA challenge (such as FIDO2, Windows Hello, or Passwordless Phone) and immediately succeeds using a lower-assurance, phishable factor (SMS, Voice call, or Push notification). This pattern is indicative of an Adversary-in-the-Middle (AiTM) attack attempting to bypass stronger authentication methods.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a suspicious authentication pattern involving 3 or more MFA failures within 15 minutes, immediately followed by an MFA success for the same user. This pattern is characteristic of potential Adversary-in-the-Middle (AiTM) activity, where an attacker intercepts a session or MFA token and relays it through separate infrastructure, while the legitimate user's own MFA attempts fail or time out.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
100
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000