Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule detects network connections from monitored devices to known cryptomining pool IP addresses and domain names. It monitors DeviceNetworkEvents for indicators of compromise (IOCs) associated with cryptomining activities, identifying potential resource hijacking on internal endpoints.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
004
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
004
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
004
Detects anomalous Telnet (TCP port 23) traffic associated with Mirai-variant botnet propagation, such as scanning for new targets or inbound compromise attempts, often following cPanel/WHM vulnerabilities.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
103
Detects potential exploitation of CVE-2026-41940 affecting cPanel/WHM, where administrative actions occur without a preceding successful login event from the same source IP within a 30-minute window. This indicates an authentication bypass attempt.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
103
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Hunters
11 days ago
001
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
201
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
101
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Hunters
11 days ago
101
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
This rule detects malicious activity associated with the Bazinga macOS backdoor, specifically focusing on the clearing of TCC privacy permissions, the staging of keychain and browser data using 'ditto', and the subsequent exfiltration of this data to a remote host via 'curl'.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
101
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
Detects indicators of the Bazinga macOS backdoor and Polygon-C2 campaign, including specific command-and-control domains, C2 infrastructure IP addresses, persistence mechanisms via launch agent property lists, and associated cryptographic indicators like file hashes and wallet addresses.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001