Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects anomalous AI agent behavior characterized by a significant spike in resource or tool invocations within a 15-minute window, potentially indicating indirect prompt injection or unauthorized agent hijacking where an agent is coerced into excessive or unauthorized actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where the Windows Package Manager (winget.exe) initiates potentially suspicious child processes such as command shells or administrative tools, and correlates this activity with network connections originating from those child processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
Detects a multi-stage process execution chain beginning with common end-user applications (browsers, Office apps, explorer.exe) spawning known LOLBins (Living-off-the-Land Binaries), which in turn execute secondary LOLBins with suspicious command-line indicators. This pattern often signifies post-exploitation activity such as secondary payload delivery, fileless malware execution, or proxy execution of malicious scripts/commands, consistent with ClickFix or BYOVD-related ingress techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects high-volume authentication failures originating from a single source IP targeting multiple unique user accounts, indicative of password spraying or credential stuffing attacks against cloud identity providers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects the suspicious creation or modification of local user accounts (e.g., 'svc_ipurple') occurring within a short 15-minute window following the execution of Windows Package Manager (Winget) configuration tasks. This behavior may indicate an attacker using automated configuration files (DSC) to establish persistence or escalate privileges on a compromised system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects MSBuild.exe establishing a network connection to a specific remote IP address (212.34.141.103) on port 4521. This behavior is indicative of MSBuild being used to proxy execution of malicious code, often associated with downloading and executing second-stage payloads or beaconing to a command-and-control (C2) server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects the loading of the 'Microsoft.Management.Configuration.dll' module by specific Windows system processes involved in package management and configuration, namely 'ConfigurationRemotingServer.exe' and 'WindowsPackageManagerServer.exe'. While these are legitimate components of the Windows Package Manager and DSC services, monitoring this activity can establish a baseline for identifying potential process injection or unauthorized library loading within these security-sensitive management binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule monitors for suspicious activities involving digital certificates. It detects PowerShell processes attempting to import a certificate into the Root store, which could indicate persistence or credential interception, and it detects the use of curl to download files named 'cert.pem' with insecure SSL settings (no certificate verification).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
303
KQL Query from file: FortiGate VPN Credential Abuse
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
10019
Detects instances where Windows Terminal (WindowsTerminal.exe) is launched by Explorer and immediately spawns a shell process (PowerShell, PWSH, or CMD), specifically excluding devices that have recorded recent RunMRU registry history. This pattern may indicate suspicious or non-interactive execution by an adversary attempting to bypass traditional shell history tracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects suspicious execution of the certutil.exe utility for file operations, specifically targeting the copying of certutil or the decoding of files with naming patterns (kid*.exe, kid*.tmp, kid*.bat) within the \Users\Public\Downloads\ directory. This pattern is commonly associated with file staging and deobfuscation of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects instances where PowerShell scripts perform Base64-encoded operations related to cryptographic functions and shortly thereafter establish network connections to known or suspect domains associated with C2 activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects ClickFix-style social engineering attacks where users are lured to 'cloudrobots.cloud' and subsequently execute malicious commands via Windows shell tools (cmd, powershell, mshta, etc.). The rule correlates browser network events to a specific domain, subsequent process launches by explorer.exe, and suspicious registry modifications associated with the Windows RunMRU, which is often abused to store and execute commands pasted by victims.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream from a file, effectively bypassing Mark-of-the-Web (MOTW) security protections. This behavior is often associated with the 'Unblock-File' cmdlet and is used by adversaries to execute downloaded malicious files without security warnings.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects the execution of 'mshta.exe' loading an .hta file containing specific suspicious terms ('VLC', 'Presentation', 'Denver'), followed by the spawning of child processes such as 'wscript.exe', 'cscript.exe', 'powershell.exe', 'cmd.exe', or 'wmic.exe'. This pattern is frequently used to proxy execution of malicious scripts via legitimate Windows binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This pattern can indicate suspicious activity where a legitimate updater process is being misused or abused to spawn additional malicious code or side-load components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects the presence of a 7-Zip library file ('7z.dll') located within a specific 'Traiolx Custom Utils' directory. The rule flags this file based on known malicious file hashes (MD5 or SHA256) or its specific file path. This is indicative of an adversary placing custom or potentially malicious tools on a system for archive manipulation or data staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of a specific Visual Basic script named 'Telegram_Private_Call_Session.vbs' by Windows scripting utilities (wscript.exe, cscript.exe) or the Microsoft HTML Application host (mshta.exe). This pattern is often associated with the execution of malicious scripts disguised as legitimate communication application components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of a PowerShell script named 'lightlife.ps1'. The rule flags instances where this specific script is invoked with bypass execution policies or when it is initiated by script hosts like wscript.exe or mshta.exe, which are common patterns for obfuscated or secondary script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003