Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects scripting interpreters (wscript.exe, cscript.exe, powershell.exe, python.exe) that perform an outbound network connection to known public Generative AI API endpoints and subsequently modify their own script file on disk. This behavior is indicative of sophisticated malware attempting to rewrite its own source code at runtime to evade signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a credential stuffing attack characterized by a high volume of failed authentication attempts from a small set of source IP addresses followed by a successful authentication within a short timeframe. This behavior is indicative of an attacker attempting to use valid credentials obtained from infostealer logs or credential leaks to gain unauthorized access to accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects MFA method resets, security info updates, or new authentication device registrations targeting privileged or administrator accounts in Azure AD/Entra ID audit logs. This activity is often indicative of social engineering campaigns, including AI-driven voice or video deepfake impersonation of employees contacting helpdesk support to gain unauthorized account access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects potential lateral movement by identifying a system that initiates SMB connections (port 445) to 5 or more unique destinations, correlated with a Windows Service installation event (Event ID 7045) on the host. This behavior is indicative of an adversary or automated tool using SMB to copy and execute binaries as a service on multiple remote systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects successful user logins from multiple geographical locations (impossible travel) where multi-factor authentication (MFA) was not utilized. This behavior is indicative of credential theft or account takeover attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects a correlation between an Active Directory Certificate Services (AD CS) certificate request (Event ID 4887) containing certificate attributes (SAN, altname, or UPN) and a subsequent Kerberos TGT request (Event ID 4768) within an hour, where the requested account name does not match the ticket user. This behavior is indicative of potential certificate-based authentication abuse, such as 'ESC1' or 'Golden Certificate' attacks where a certificate is requested and immediately used for credential impersonation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the use of common administrative tools (vssadmin, wbadmin, wmic, bcdedit, etc.) to perform actions that inhibit system recovery. This includes deleting Volume Shadow Copies, deleting backup catalogs, disabling system recovery boot policies, and stopping backup-related services, which are common behaviors used by ransomware to prevent data restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects anomalous child process execution (e.g., shells, curl, python) or the creation of web-accessible script files (.jsp, .php, .aspx) originating from common VPN gateway or edge appliance service processes. This behavior is indicative of potential exploitation of a remote-facing appliance or webshell deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects suspicious activity on VMware ESXi hosts involving the termination or unregistration of virtual machines via 'esxcli' or 'vim-cmd', correlated with high volumes of file modification or creation events (.vmdk or .vmx files) within a short window. This pattern often indicates attempts to disrupt virtual machines or inhibit system recovery by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the installation of a new Windows service where the executable path is located in suspicious or uncommon directories (e.g., Temp, Users, AppData) or uses known living-off-the-land binaries (LotLBin) in the command path. This pattern is commonly used by adversaries for persistence and privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) using weak encryption (RC4/0x17) directed at multiple unique Service Principal Names (SPNs) from a single host or user within a short timeframe. This behavior is indicative of Kerberoasting, a technique used by attackers to harvest service account credentials for offline brute-force cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a single host or account generating a high volume of LDAP queries (typical of reconnaissance tools like BloodHound/SharpHound) within a 10-minute time window. The rule specifically looks for more than 500 LDAP queries targeted at a limited number of Domain Controllers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where PowerShell is executed with encoded commands, seemingly spawned by a process masquerading as or related to the Microsoft Edge Update Task. The rule specifically monitors for process chains involving 'conhost.exe' with '--headless' arguments and subsequent PowerShell execution containing encoded commands, often associated with obfuscated activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects SAML token authentication events where the token-signing certificate does not match the established federation baseline (indicating potential token forging or unauthorized IdP activity) or where critical conditional access claims (MFA and device compliance) are missing from the SAML assertion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects NTLM network logon events (Logon Type 3) using the NtLmSsp process where the key length is zero. This pattern is often indicative of Pass-the-Hash (PtH) attacks where the adversary uses a NTLM hash for authentication without knowing the original plaintext password.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
This rule detects two suspicious patterns related to authentication: (1) 'MFA Fatigue' or 'Push Bombing' where a user experiences a high volume of MFA push denials followed by an acceptance in a short timeframe, and (2) potential account takeover where a help-desk initiated password reset is followed by an MFA re-registration or new device enrollment by the same user within 30 minutes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the creation or writing of disk image files (.iso, .img, .vhd, .vhdx) followed by the execution of suspicious file types (.lnk, .exe, .js, .vbs, .cmd, .bat, .scr) by explorer.exe within a 10-minute window. This behavior is indicative of an adversary using container files to bypass security controls or execute malicious payloads from mounted images.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects usage of the Windows certutil.exe utility with flags commonly used by adversaries to download files from remote URLs or decode base64 encoded files. These techniques are often utilized for ingress tool transfer or deobfuscating malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the execution of PowerShell commands that enumerate files within sensitive user directories such as Desktop, Downloads, Documents, or OneDrive, using common cmdlets like Get-ChildItem with recurrence or filtering. This behavior is indicative of an adversary attempting to discover or stage files for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004