Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the activity of the PIVOTPIPE .NET loader, which involves writing specific artifacts (core.pak, agent.json, pk.der, or sleepmask.o) to a temporary directory with the 'nb_' prefix or the creation of debug files containing strings associated with in-memory reflective loading of a remote access tool (RAT).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule detects activity matching known indicators of compromise (IOCs) associated with recent Russian espionage campaigns, including malicious domains, IP addresses, email senders, file names, and file hashes. It monitors network, sign-in, email, process, and file events across enterprise systems.
avatar
F S@Fsdr
avatar
Detections.ai Community
25 days ago
604
Detects the execution of PowerShell scripts located in the user's temporary folder. The detection logic looks for common obfuscation flags such as WindowStyle Hidden, NoProfile, and NoLogo, combined with the -File argument, which are frequently used by droppers and malicious payloads to execute scripts in the background while evading immediate user observation.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
003
Detects the loading of 'libcurl.dll' or related DLL patterns from suspicious directories such as '\Microsoft\Crypto\RuntimeBroker\', often associated with process masquerading or side-loading activities. The rule also monitors for the execution of suspicious binaries ('Tax_Notice_45594.exe') or binaries that mimic 'Notepad++' metadata from within these paths.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
402
This rule detects outbound network connections from internal devices to a list of known malicious IP addresses associated with adversary command and control infrastructure. The rule specifically monitors connections over common ports, potentially indicating established communication with malicious servers.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
002
This rule detects the presence or execution of a specific file on a device, identified by its SHA256 hash. The rule monitors both file creation/access and process execution events to identify if a known malicious binary is interacting with the system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
002
This rule monitors DeviceFileEvents and DeviceProcessEvents for the execution or presence of files matching a predefined list of known malicious SHA256 hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
002
This rule monitors for the presence of files matching a known list of malicious SHA256 hashes on devices. It correlates these file events with process creation events occurring on the same device within a 10-minute window, identifying potential execution of malicious binaries or artifacts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
002
Detects thread creation events where the initiating module is ntdll.dll, bypassing the conventional CreateThread path originating from kernel32.dll. This is a common behavioral indicator of process injection techniques used to hide malicious thread execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects network activity associated with the HEAVYGRAM PowerShell implant, specifically identifying outbound traffic to the Telegram Bot API (api.telegram.org). The rule looks for established connections and HTTP requests containing Telegram bot-specific URI patterns ('/bot', '/getUpdates') coupled with a 'WindowsPowerShell' user agent, indicating an automated beaconing mechanism used for command and control.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
17015
This rule detects command line patterns associated with common Impacket tools (wmiexec, psexec, smbexec) executed via Windows processes (cmd.exe, powershell.exe) or via network connections to ports 445 and 135 initiated by Python processes. These tools are frequently used by adversaries for lateral movement, remote service execution, and command execution on compromised systems.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
205
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
002
This rule detects suspicious activity involving the creation of scheduled tasks for persistence using command-line arguments indicative of tool execution (e.g., chisel, powershell) or the direct execution of hidden PowerShell scripts intended to bypass execution policy.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
102
This rule detects suspicious activity involving the creation of scheduled tasks for persistence using command-line arguments indicative of tool execution (e.g., chisel, powershell) or the direct execution of hidden PowerShell scripts intended to bypass execution policy.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
002
This rule detects suspicious activity involving the creation of scheduled tasks for persistence using command-line arguments indicative of tool execution (e.g., chisel, powershell) or the direct execution of hidden PowerShell scripts intended to bypass execution policy.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
102
Detects the execution of PowerShell with commands intended to modify or interact with Windows Registry Run keys, a common technique for establishing persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of PowerShell with commands intended to modify or interact with Windows Registry Run keys, a common technique for establishing persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
This rule detects the use of the 'Add-MpPreference' PowerShell cmdlet with the '-ExclusionPath' argument to add specific file or directory paths to Microsoft Defender's exclusion list. This behavior is a common technique used by adversaries to bypass security controls by ensuring malicious tools or scripts are not scanned by Windows Defender. The rule specifically alerts on exclusions related to common staging areas or specific tools such as Telegram Desktop, SSH cache folders, and package management directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects when common torrent client applications spawn a child process that is an executable. This behavior is often associated with the execution of malicious payloads delivered or masqueraded as files within torrent environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
This rule detects modifications to the Windows 'Run' registry key intended to achieve persistence by launching potentially malicious executables named 'RuntimeSSH.exe' or 'winappx.exe'. Attackers often use these paths to ensure that their malicious code executes automatically upon user login.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Page 302 of 1871