Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects a specific pattern associated with AvisLoader or similar malware: a device establishes a network connection to known Cloudflare Tunnel infrastructure domains (trycloudflare.com or workers.dev), followed by the creation and execution of an executable file (.exe, .dll, or .scr) in user-writable directories such as Downloads, AppData, or Temp within a 15-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
This rule detects the presence and execution of known suspicious files (hashes provided) or specific malicious artifacts, such as 'hmn_hook.dll' being loaded, or the execution of binaries named 'auto.exe' and '78324.exe' associated with specific command-line arguments. It monitors file events, image loads, and process creation to identify potential malware activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
This rule detects potential quishing (QR code phishing) attempts by identifying emails with one or more image attachments and minimal URL content, followed by a risky user authentication event within a 3-hour window. This behavior is indicative of an attacker attempting to harvest credentials via a malicious QR code that redirects the user to a phishing site.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101
Detects high-volume, rapid enumeration of core Microsoft Graph directory endpoints (users, groups, applications, and servicePrincipals) by a single identity or session. This behavior is indicative of reconnaissance tools such as AADInternals, ROADtools, or TokenTactic being used to map out a cloud environment's directory structure.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
101
Detects Microsoft Entra ID service principal (app-only) sign-in events where an application accesses a resource or tenant that has not been observed in the previous 30 days. This is often an indicator of cross-tenant impersonation abuse or credential misuse, particularly related to Actor Tokens.
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
001
Detects scenarios where a user registers a new WebAuthn/Passkey credential and subsequently performs a sign-in from a different network or device shortly after, preceded by a sign-in from a risky or non-passkey-based method. This pattern is often associated with credential abuse or MFA registration hijacking.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
101
Detects scenarios where a user registers a new WebAuthn/Passkey credential and subsequently performs a sign-in from a different network or device shortly after, preceded by a sign-in from a risky or non-passkey-based method. This pattern is often associated with credential abuse or MFA registration hijacking.
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
101
Detects scenarios where a user registers a new WebAuthn/Passkey credential and subsequently performs a sign-in from a different network or device shortly after, preceded by a sign-in from a risky or non-passkey-based method. This pattern is often associated with credential abuse or MFA registration hijacking.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
This rule identifies instances of screen capture events initiated by processes that have previously engaged in network communication with known Remote Management Tool (RMM) domains. By correlating network activity with suspicious endpoint events, it flags potential unauthorized screen scraping performed by tools often abused by attackers for post-compromise reconnaissance.
avatar
F S@Fsdr
avatar
Detections.ai Community
21 days ago
9015
This rule detects potential quishing (QR code phishing) attempts by identifying emails with one or more image attachments and minimal URL content, followed by a risky user authentication event within a 3-hour window. This behavior is indicative of an attacker attempting to harvest credentials via a malicious QR code that redirects the user to a phishing site.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects Microsoft Entra ID service principal (app-only) sign-in events where an application accesses a resource or tenant that has not been observed in the previous 30 days. This is often an indicator of cross-tenant impersonation abuse or credential misuse, particularly related to Actor Tokens.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects the addition or modification of federated domain trusts or identity provider settings within Entra ID. Such actions can be indicative of attackers establishing persistent access or implementing Golden SAML-style attacks by forging authentication assertions via a compromised or malicious identity trust.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Detects Microsoft Entra Privileged Identity Management (PIM) activations for high-privileged roles (e.g., Global Administrator) that occur outside of defined business hours or are performed without an associated justification or ticket number. This helps identify potentially unauthorized or abnormal use of elevated privileges.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects malformed HEIF/HEIC image files with anomalous ftyp/box structure consistent with the libheif memory corruption exploit (CVE-2026-32882) used against Discourse forum image upload endpoints
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
005
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
22036
Detects high-volume, rapid enumeration of core Microsoft Graph directory endpoints (users, groups, applications, and servicePrincipals) by a single identity or session. This behavior is indicative of reconnaissance tools such as AADInternals, ROADtools, or TokenTactic being used to map out a cloud environment's directory structure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects a single user identity performing bulk destructive device actions (wipe, retire, remote lock, or delete) against multiple distinct devices within a short timeframe. This activity is indicative of potential unauthorized access and destructive intent, mirroring techniques observed in large-scale cloud-based identity compromise incidents.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects scenarios where a user registers a new WebAuthn/Passkey credential and subsequently performs a sign-in from a different network or device shortly after, preceded by a sign-in from a risky or non-passkey-based method. This pattern is often associated with credential abuse or MFA registration hijacking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
001