Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects instances where a trusted, system-protected executable loads a DLL file from a user-writable or temporary directory that is not digitally signed or has an invalid signature. This is a common indicator of DLL side-loading or DLL hijacking, where an adversary attempts to execute malicious code by placing a malicious DLL in a location searched by a legitimate process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the use of the BITSAdmin command-line utility to perform file downloads or add files to a transfer job. Adversaries may abuse the Background Intelligent Transfer Service (BITS) for downloading malicious files while evading detection or maintaining persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects a sequence of suspicious identity activities indicative of a post-account-takeover pivot. The rule identifies a user profile engaging in corporate VPN SAML SSO probing, triggering a MFA enrollment interrupt in Azure, and subsequently accessing multiple Microsoft 365 applications (Azure Portal, OfficeHome, SharePoint) within a 30-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects a malicious execution chain starting with an MSI file being launched by explorer.exe from user-downloaded folders. The installer spawns chrome.exe, drops a specific loader file (e.g., PavokwiLoader.exe or Loader.exe) into the %LOCALAPPDATA%\Temp\modules\ directory, and establishes persistence via the HKCU 'Load' registry value pointing to that location.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects high-volume account existence checks targeting the Microsoft Teams API. The rule identifies anomalous authentication attempts characterized by the use of outdated Electron/Chrome user-agent strings associated with the TeamFiltration tool, specifically targeting the Microsoft Teams API AppId (1fec8e78-bce4-4aaf-ab1b-5451cc387264).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects execution of potentially malicious processes (mshta, powershell, cmd, conhost) which are common vectors for ClickFix-style attacks, where a user is socially engineered into copying and pasting malicious commands into the Windows Run dialog or a command prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects suspicious processes such as PowerShell, Python, or scripting hosts performing network communication with major AI/LLM provider APIs, followed immediately by child process execution or related activity. This pattern is indicative of LLM-assisted automation for malicious activities, potentially using AI to generate code, scripts, or orchestrate command and control actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where a user successfully authenticates via the OAuth Device Code flow using an unmanaged or non-compliant device, followed closely by high-privileged Azure/Graph API administrative actions within a short timeframe. This behavior is indicative of a device-code phishing attack aimed at bypassing MFA controls, including FIDO2/passkeys, by compromising an active session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects potential Adversary-in-the-Middle (AiTM) session token theft by monitoring for an initial interactive sign-in followed shortly by a non-interactive token refresh from a different IP address and browser fingerprint without a multi-factor authentication (MFA) challenge. This behavior is indicative of an adversary replaying captured session cookies via reverse-proxy infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects potential Adversary-in-the-Middle (AiTM) session token theft by monitoring for an initial interactive sign-in followed shortly by a non-interactive token refresh from a different IP address and browser fingerprint without a multi-factor authentication (MFA) challenge. This behavior is indicative of an adversary replaying captured session cookies via reverse-proxy infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where a user successfully authenticates via the OAuth Device Code flow using an unmanaged or non-compliant device, followed closely by high-privileged Azure/Graph API administrative actions within a short timeframe. This behavior is indicative of a device-code phishing attack aimed at bypassing MFA controls, including FIDO2/passkeys, by compromising an active session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000