Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
Detects changes to the Access Control List (ACL) of the AdminSDHolder object in Active Directory. AdminSDHolder is a protected object whose ACL is automatically propagated by the SDProp process every 60 minutes to all privileged groups and accounts in the domain. Modifying the ACL on this object allows an adversary to establish a durable, self-healing backdoor by granting persistent access to high-privileged security principals.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
Detects indicators of the Bazinga macOS backdoor and Polygon-C2 campaign, including specific command-and-control domains, C2 infrastructure IP addresses, persistence mechanisms via launch agent property lists, and associated cryptographic indicators like file hashes and wallet addresses.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Detects the use of the Windows Terminal Services console tool (tscon.exe) to hijack active or disconnected Remote Desktop sessions. Attackers often execute this with SYSTEM privileges, frequently initiated via service control utilities like sc.exe, schtasks.exe, or services.exe, to gain unauthorized access to user sessions without requiring credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects the misuse of the legitimate odbcconf.exe utility via the /A switch combined with the REGSVR action. Attackers leverage this behavior to execute malicious DLLs, often utilizing response files or executing from non-standard directories to bypass application control policies.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Detects the creation of a scheduled task configured to run under SYSTEM or a Service account, where the triggering process is not a recognized system binary (e.g., taskeng.exe, schtasks.exe). This pattern is often used for persistence or lateral movement by bypassing standard administrative task creation tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
007
Detects the use of sdbinst.exe to install a shim database (.sdb) file from non-standard, user-writable directories (such as Temp, AppData, Downloads, Users Public, or ProgramData). Adversaries use application shimming to achieve persistence or privilege escalation, and custom shims are typically expected to reside in system-protected AppPatch directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
This rule detects executions of the 'osascript' utility on macOS where the command line argument is exceptionally long and contains high entropy, suggesting the use of base64 or other encoding techniques to obfuscate malicious scripts or payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Detects network connection attempts to known malicious infrastructure, specifically targeting suspicious domains and an IP address associated with command and control (C2) activity. The rule monitors endpoint network events for communication with specified malicious URLs or a hardcoded IP.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
This rule detects potentially malicious network activity by monitoring for specific query parameters ('bmodule', 'smodule', 'lmodule', 'task', 'upload.php') in web requests or communication with a specific known-malicious IP address ('62.60.226.50'). This pattern is characteristic of C2 (Command and Control) traffic or unauthorized file staging/upload operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Detects the use of common scripting and command-line utilities (such as curl, python, or bash) to interact with known Polygon blockchain RPC endpoints or specific smart contract addresses/selectors, which may indicate unauthorized interaction with decentralized applications or crypto-assets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
101
Detects the execution of command-line sequences associated with the second stage of ClickFix-style malware (often linked to AMOS or fake-Xcode campaigns). This rule looks for the concatenation of hex decoding (xxd), AES decryption (openssl), decompression (gunzip), and subsequent evaluation (eval) of a shell variable, which is a signature pattern for decrypting and executing malicious payloads in memory.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
001
Detects network connections or DNS queries to known suspicious domains associated with command and control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects execution of MeshAgent binaries when initiated by common scripting or application processes (e.g., java, sh, bash, python) or when displaying suspicious command-line patterns indicative of unauthorized remote access or download activity, particularly in environments like WebLogic or PeopleSoft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects a specific pattern associated with AvisLoader or similar malware: a device establishes a network connection to known Cloudflare Tunnel infrastructure domains (trycloudflare.com or workers.dev), followed by the creation and execution of an executable file (.exe, .dll, or .scr) in user-writable directories such as Downloads, AppData, or Temp within a 15-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
This rule detects the presence and execution of known suspicious files (hashes provided) or specific malicious artifacts, such as 'hmn_hook.dll' being loaded, or the execution of binaries named 'auto.exe' and '78324.exe' associated with specific command-line arguments. It monitors file events, image loads, and process creation to identify potential malware activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001