Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects the creation of a .bat file in the Windows Startup directory, followed by the execution of a command process from a temporary location using a specific command line pattern. This behavior is indicative of persistent malware or a dropper attempting to execute an initial payload upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule monitors for two potentially suspicious activities on Windows systems: the creation of scheduled tasks named 'MicrosoftEdgeUpdateTask' or 'MicrosoftEdgeUpdateTaskCore' using 'schtasks.exe', and the execution of scripts via 'wscript.exe' with silent flags ('//B' and '//Nologo'). These behaviors are often associated with persistence mechanisms or the execution of obfuscated/malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects a coordinated attack sequence where a browser process is terminated, followed immediately by the execution of an unsigned Python interpreter from a suspicious location (temp/downloads folder), which is then followed by the installation of an unsigned browser extension. This pattern mimics ClickFix and browser-based RAT lure campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects unauthorized processes attempting to read or modify Discord's local storage leveldb files, which store user authentication tokens, and correlates this with suspicious network activity to Discord's API or the presence of token-stealing keywords in command-line arguments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects potential usage of Hidden VNC (hVNC) tools by monitoring for specific command-line arguments (such as 'hvnc-input', 'hvnc-desktop', or 'HVNC_Telegram') and Windows events related to the creation or switching of desktops (e.g., 'CreateDesktop', 'SwitchDesktop'). hVNC is a common technique used by malware to establish a hidden remote desktop session for unauthorized access and control without alerting the user.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects MFA push-bombing or authentication fatigue attacks where an adversary repeatedly triggers MFA challenge requests for a user in a short period, potentially from multiple IP addresses, culminating in a successful authentication event. This behavior is indicative of an attacker attempting to coerce a user into approving an MFA request.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects anomalous authentication behavior consistent with Adversary-in-the-Middle (AiTM) phishing attacks, specifically where an MFA-authenticated session is accessed from multiple, disjoint geographic locations or IP addresses within a short timeframe, indicating the replay of stolen session tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects anomalous authentication behavior consistent with Adversary-in-the-Middle (AiTM) phishing attacks, specifically where an MFA-authenticated session is accessed from multiple, disjoint geographic locations or IP addresses within a short timeframe, indicating the replay of stolen session tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the installation or loading of a non-standard kernel driver followed by the termination of known security/EDR agent processes. This behavior is indicative of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where attackers leverage kernel-level privileges from a vulnerable driver to bypass EDR protections and disable security tools prior to encryption or other malicious activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a suspicious pattern of mass security process termination, where a process masquerading as legitimate consumer or gaming software (e.g., Kaspersky, Valorant, Javelin) repeatedly uses commands like taskkill, sc stop, or NtTerminateProcess to disable EDR agents and antivirus software within a short time window. This behavior is indicative of pre-ransomware staging activities used by threat actors.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a suspected ransomware double-extortion sequence: the bulk creation of password-protected archives using compression utilities (e.g., 7z, RAR), followed by significant outbound network connections to common cloud storage or anonymization endpoints, and concluding with mass file modifications indicative of encryption activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects anomalous activity in a CI/CD environment where a runner process accesses sensitive credential files (such as PyPI tokens or GitHub secrets) followed closely by a network connection to public package registry domains, potentially indicating a supply-chain compromise where stolen credentials are used to publish malicious packages.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects package publishing or version creation events on npm or PyPI that originate from non-CI/CD service accounts, suggesting the use of stolen registry authentication tokens by unauthorized entities to push malicious package versions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects unauthorized, unsigned processes accessing sensitive browser files (Cookies, Login Data, Local State) across common browsers (Chrome, Edge, Brave, Firefox) followed by an outbound network connection. This behavior is indicative of credential-harvesting infostealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects anomalous AI agent behavior characterized by a significant spike in resource or tool invocations within a 15-minute window, potentially indicating indirect prompt injection or unauthorized agent hijacking where an agent is coerced into excessive or unauthorized actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where the Windows Package Manager (winget.exe) initiates potentially suspicious child processes such as command shells or administrative tools, and correlates this activity with network connections originating from those child processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
Detects a multi-stage process execution chain beginning with common end-user applications (browsers, Office apps, explorer.exe) spawning known LOLBins (Living-off-the-Land Binaries), which in turn execute secondary LOLBins with suspicious command-line indicators. This pattern often signifies post-exploitation activity such as secondary payload delivery, fileless malware execution, or proxy execution of malicious scripts/commands, consistent with ClickFix or BYOVD-related ingress techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects high-volume authentication failures originating from a single source IP targeting multiple unique user accounts, indicative of password spraying or credential stuffing attacks against cloud identity providers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects the suspicious creation or modification of local user accounts (e.g., 'svc_ipurple') occurring within a short 15-minute window following the execution of Windows Package Manager (Winget) configuration tasks. This behavior may indicate an attacker using automated configuration files (DSC) to establish persistence or escalate privileges on a compromised system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects MSBuild.exe establishing a network connection to a specific remote IP address (212.34.141.103) on port 4521. This behavior is indicative of MSBuild being used to proxy execution of malicious code, often associated with downloading and executing second-stage payloads or beaconing to a command-and-control (C2) server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects the loading of the 'Microsoft.Management.Configuration.dll' module by specific Windows system processes involved in package management and configuration, namely 'ConfigurationRemotingServer.exe' and 'WindowsPackageManagerServer.exe'. While these are legitimate components of the Windows Package Manager and DSC services, monitoring this activity can establish a baseline for identifying potential process injection or unauthorized library loading within these security-sensitive management binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003