Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects a multi-stage Business Email Compromise (BEC) attack involving executive impersonation via look-alike domains, followed by the creation of suspicious inbox rules (forwarding/deletion) by the victim, and concurrent external communication (Teams/Zoom meeting invites) from a newly created account. It correlates these activities to identify sophisticated payment fraud campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects unauthorized data staging activities using archival utilities followed by data exfiltration to known public cloud storage providers. The rule specifically excludes hosts experiencing mass file renaming activity, focusing on extortion-only scenarios where data is stolen without encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a sequence of events indicative of Bring Your Own Vulnerable Driver (BYOVD) exploitation. The rule correlates the creation of a new service with kernel-mode drivers, the loading of a signed driver, and the subsequent termination or disabling of common EDR security processes within a short timeframe, suggesting the exploitation of the driver to bypass EDR defenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects potential 'Quishing' (QR code phishing) attempts by identifying email-based phishing detection or malicious URL indicators followed by a user clicking the URL and subsequently authenticating to a corporate system from a mobile device (Android or iOS) within a 30-minute window. This behavior often suggests an adversary successfully harvesting credentials via a QR code link and then using them to gain unauthorized access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the use of legitimate Windows administrative tools (vssadmin, wmic, wbadmin, bcdedit, sc, net) to delete volume shadow copies, clear backup catalogs, disable boot recovery options, or stop critical backup and system services. This behavior is highly characteristic of ransomware activity aiming to prevent data restoration and system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of 'tscon.exe', a Windows utility used to control Remote Desktop sessions. The rule specifically alerts when 'tscon.exe' is executed with parameters indicative of session hijacking (such as '/dest:') or when it is invoked by suspicious processes or under SYSTEM privileges, which are characteristic of RDP session hijacking techniques used for privilege escalation and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of known Living-off-the-Land Binaries (LOLBAS) like mshta, rundll32, regsvr32, and others, when the command line includes indicators of external network retrieval (http/ftp), script execution (javascript/vbscript), or common obfuscation/decoding patterns (base64, encodedcommand). The rule excludes paths within System32 and SysWOW64 to focus on potentially suspicious locations or renamed binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects potential Kerberoasting activity by identifying an abnormal volume of RC4-encrypted Ticket Granting Service (TGS) requests (Event 4769) targeting service accounts, followed closely by a successful logon (Event 4624) from a previously dormant service account, suggesting the successful use of a cracked service ticket for unauthorized authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects attempts to tamper with, disable, or delete audit logging configurations in AWS CloudTrail and Azure Monitor. Monitoring these activities is critical to ensure that audit logs remain intact for security investigations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects potential credential dumping activity via DCSync, identified by a non-DC computer account performing directory replication (DRS GetNCChanges), correlated with subsequent suspicious Kerberos ticket requests (Event ID 4769) that utilize weak encryption (RC4 or legacy DES), which is often associated with Golden Ticket abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
No description available.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where a user successfully authenticates to a cloud service (Azure AD) from an unrecognized ASN, device, or country without performing MFA, followed shortly by high-risk actions such as mailbox rule creation, mass file downloads, or OAuth application registration. This pattern is indicative of session cookie theft or OAuth token replay used to bypass MFA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a ClickFix-style activity where an adversary uses nslookup.exe or certutil.exe to perform DNS TXT record queries for payload staging or C2 rendezvous. The rule identifies suspicious parent processes like explorer.exe or scripting hosts, correlates this with a subsequent outbound network connection from the same host, and is intended to capture DNS-based beaconing or data staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the clearing of Windows Event Logs via wevtutil, PowerShell, or registry modification, occurring within one hour of a remote interactive or network logon event on the same host. This pattern is indicative of anti-forensic activity often performed following lateral movement or prior to destructive actions like ransomware deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a suspicious pattern consistent with rapid handoff from an initial access broker to an operator: a user account is added to a privileged group (e.g., Domain Admins) followed within 5 minutes by successful logins to 3 or more distinct hosts. This behavior indicates immediate privilege escalation followed by rapid lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a sequence of activity indicative of data exfiltration preparation. This rule identifies the creation of multiple large archive files (.zip, .rar, .7z) in temporary or staging directories on an endpoint, followed by a network connection transferring a significant volume of data to an external, non-private IP address within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of PsExec by identifying the creation of the PSEXESVC remote service or its associated named pipe. It also identifies renamed or masqueraded PsExec binaries by checking file metadata and provides a mechanism to flag unusual source-to-target host account pairings often associated with lateral movement via SMB/Admin Shares.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects specific file artifacts associated with an AsyncRAT infection chain that leverages a renamed AutoIT interpreter. The rule looks for the presence of a renamed executable, an encrypted .ini loader script, and an unnamed binary payload staged within a temporary directory, as well as associated batch script activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003