Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
000
This rule detects potential web shell creation on a Microsoft Exchange server by monitoring for suspicious child processes spawned by the IIS web server process (w3wp.exe) that correlate with the creation or modification of web-accessible script files (.aspx, .ashx, .asp, .dll) within the Exchange virtual directories (ecp, owa, aspnet_client). This pattern is consistent with common post-exploitation activities used by attackers to gain persistent access via web shells.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
This rule detects HTTP requests directed at Microsoft Exchange Outlook Web Access (OWA) that contain suspicious 'fakePath' and 'fakePageName' parameters in the URI. These parameters are indicators of the 'GhostContainer' malware attempting to establish a socket forwarding proxy through the web server to facilitate command and control communications.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
Detects the GhostContainer .NET-based backdoor assembly deployed on compromised Microsoft Exchange servers, requiring multiple corroborating unique indicators (C2 header, proxy class name, virtual path parameters) alongside .NET/PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
002
Detects the GhostContainer .NET-based backdoor assembly deployed on compromised Microsoft Exchange servers, requiring multiple corroborating unique indicators (C2 header, proxy class name, virtual path parameters) alongside .NET/PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
Detects anomalous MS_T120 channel binding and MCS handshake patterns characteristic of the BlueKeep (CVE-2019-0708) remote code execution vulnerability in Microsoft RDP services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
002
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
002
Detection rules identifying malformed RDP MCS Connect Initial PDUs and unusual service crashes following RDP connection attempts, both indicative of exploitation attempts against the CVE-2019-0708 (BlueKeep) vulnerability.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
002
Detection rules identifying malformed RDP MCS Connect Initial PDUs and unusual service crashes following RDP connection attempts, both indicative of exploitation attempts against the CVE-2019-0708 (BlueKeep) vulnerability.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
002
Detection rules identifying malformed RDP MCS Connect Initial PDUs and unusual service crashes following RDP connection attempts, both indicative of exploitation attempts against the CVE-2019-0708 (BlueKeep) vulnerability.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
26 days ago
105
Detects the execution of BloodHound/SharpHound reconnaissance tools and the presence of their generated output files (ZIP or JSON format) on a host. This rule monitors both the process creation events associated with the tool's execution and file creation events indicative of data staging or collection output.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
015
Detects network activity (DNS queries or direct IP communication) associated with 'ClickFix' social engineering attacks targeting users under the guise of an HBO Max update or repair utility. The rule includes indicators for known malicious domains and IP addresses while incorporating filters to minimize false positives from security scanners, threat intel feeds, and automated crawlers by analyzing User-Agent strings and network source addresses.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
003
This rule detects anomalous access patterns on a specific IIS host (agent.3bb.co.th) by comparing recent traffic against a 30-day historical baseline. It identifies requests from accounts or source IPs not seen in the baseline, activity occurring during off-hours, or traffic from external sources. The rule further filters for high-volume or high-path diversity requests, which are indicative of automated reconnaissance or potential brute-force activity against the web application.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
003
This rule detects the creation of a local user account using the 'net.exe' or 'net1.exe' utility where the command line contains a specific hardcoded password ('Numlock!123'). This pattern is indicative of automated or manual post-exploitation activities, such as creating a back-door account for persistent access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of s5cmd.exe with command line arguments indicative of data transfer operations (sync, cp, mv, run) to or from an 's3://' URI. s5cmd is a high-performance command-line tool frequently used for parallel S3 operations, which may be leveraged by adversaries for rapid data exfiltration or staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of known Remote Monitoring and Management (RMM) agent installers or binaries via PowerShell. This activity may indicate an attempt to establish unauthorized remote access to a system, a common technique used by threat actors to maintain persistence or conduct post-compromise activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
This rule monitors for the execution of 'net.exe' or 'net1.exe' with command line arguments containing 'user', '/add', and a specific suspicious string 'Numlock!123'. This pattern is indicative of an adversary attempting to create a local user account on a Windows system using a hardcoded or known adversary credential.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Page 305 of 1871