Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the modification of service permissions for the 'AgtaBackupAgentSvc' service using the 'sdset' command via 'sc.exe', 'cmd.exe', or 'powershell.exe'. Adversaries use this technique to hide services or modify access to them by applying a specific Service Descriptor Definition Language (SDDL) string to bypass security enumeration or maintain persistence.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
102
Detects the execution of PowerShell from processes associated with legitimate Remote Monitoring and Management (RMM) tools (such as ScreenConnect or LogMeIn) running under the SYSTEM account. This behavior is indicative of an attacker who has gained access to an RMM tenant and is using an interactive session to execute commands, perform reconnaissance, or deploy further malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
202
Detects the disabling of the built-in 'Administrator' account initiated by a system-level process (e.g., service or background task), which is characteristic of GPO enforcement or malicious tampering.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
002
Detects the execution of known PAYLOAD ransomware process-termination utilities (killer.exe or kill.exe). These tools are used by adversaries to forcefully terminate security software, backup services, and database processes prior to file encryption.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
002
Detects execution of common Windows utilities used by adversaries post-encryption to hinder system recovery and clear forensic evidence. This includes disabling the Windows Recovery Environment (ReAgentC), wiping disk free space (Cipher), clearing DNS caches, and clearing Windows Event Logs via Wevtutil or PowerShell.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
002
Detects the creation of new Group Policy Objects (GPOs), linking of GPOs at the domain root level, or modifications to existing GPOs that include 'Firewall' in their configuration settings. These activities are common precursors or indicators of persistence mechanisms and defensive bypass attempts by adversaries seeking to weaken security controls or maintain unauthorized access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
002
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
006
This rule detects potential malicious activity where a non-browser process downloads a specific payload file from a suspicious domain ('easyllms.xyz') and is subsequently linked to process activity involving the discovery of system or user information (e.g., GetComputerNameA, GetUserNameA). This pattern is characteristic of a dropper or stage-one malware attempting to profile the compromised host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
002
This rule detects potential command and control (C2) beaconing activity where specific suspicious API endpoints (/api/v1/ping.php and /api/v1/connect.php) are accessed by common system processes (msedge_proxy.exe or WindowsUpdate.exe). The logic clusters these network requests by device and process, triggering an alert when both endpoints are observed from the same process on a single device, a common indicator of a C2 communication pattern.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
202
Detects the execution of a file named 'msedge_proxy.exe' located in temporary directories (AppData\Local\Temp or Windows\Temp). The rule excludes processes initiated from legitimate Microsoft Edge installation paths, and flags processes that are either spawned simultaneously with the parent or are not spawned by explorer.exe, indicating potential masquerading or unauthorized execution of a malicious file disguised as a browser component.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
102
This rule detects potential brute force or account compromise attempts by identifying user accounts that have successfully authenticated or initiated authentication events from two or more distinct IP addresses within the observed time window. It monitors Windows Event IDs 4624 (Successful Logon), 4648 (Logon attempted using explicit credentials), and 4776 (The domain controller attempted to validate the credentials for an account).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
4152
Detects instances where common scripting or development language runtimes (Go, Node.js, WScript, CScript) access sensitive configuration or credential files, such as AWS credentials, Kubernetes configs, SSH keys, or environment files. This activity is often indicative of credential harvesting or unauthorized access to sensitive secrets by potentially malicious scripts or processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
408
Detects the 'ClickFix' social engineering pattern where an adversary tricks a user into using the Windows Run dialog (explorer.exe) to execute msiexec.exe, downloading and installing a remote MSI package. This is frequently associated with malware delivery, such as Psychedelic Stealer, where users are prompted to copy and paste malicious commands under the guise of fake error messages or CAPTCHAs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects potential exfiltration staging by copying files from Windows mounts (/mnt/) into the WSL Linux filesystem using wsl.exe -e cp/mv
avatar
Trevor Moore@gr4dyb4by
avatar
Detections.ai Community
16 days ago
4014
Detects Microsoft Installer (MSI) files associated with the psychedelic stealer malware family. The rule identifies MSI components that contain embedded paths to the psychedeliclove.exe payload, specific command and control IP/port combinations, and decoy file names (e.g., MsMpEng.exe or explorer.exe) used to disguise the malware installation or execution process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the creation of a Windows service that impersonates the legitimate Windows Time (w32time) service name or display name but utilizes a binary located outside of the standard system32 directory. This behavior is indicative of a persistence mechanism, often used by backdoors like RemotePanel to evade detection after initial compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
This rule detects persistence mechanisms involving the creation or modification of Windows Registry Run keys, the creation of scheduled tasks, or the execution of specific binaries (COTFileReadApp.exe, DeElevate64.exe) associated with potentially unauthorized activity, specifically tracking strings related to 'Canon Configuration Reader' or 'Stardock DeElevation Tool'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
202
Detects a credential-theft pattern associated with Psychedelic Stealer where a process accesses the 'Login Data' file of common Chromium-based browsers, followed shortly by a network connection to a known stealer exfiltration API endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
This rule detects the creation of a new Windows service using common administrative tools like sc.exe or PowerShell's New-Service cmdlet that masquerades as the legitimate Windows Time service (w32time). The rule specifically flags service creation commands that use relevant service names but point to non-standard, suspicious executable paths or configurations, potentially indicating persistence or malicious activity by RemotePanel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
202
Detects the loading of spoofed system DLLs (dnsapi.dll or ws2_32.dll) from non-system directories, followed by network beaconing to suspicious domains associated with the NeedyMantis malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the execution of taskkill.exe to terminate known security software processes, when the command is initiated from sqlservr.exe or via a command shell child process of sqlservr.exe. This activity is a common post-exploitation step after abusing xp_cmdshell to neutralize defenses before deploying further payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Page 31 of 1866