Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
001
Detects high-volume deletion or recycling of files within OneDrive or SharePoint for a specific user, which may indicate malicious activity such as data destruction, ransomware, or unauthorized data exfiltration staging.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
4012
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
001
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
101
This rule detects command-line activity where a remote resource is downloaded via 'curl', decoded using 'base64', and then piped directly into a shell interpreter (sh, bash, or zsh). This pattern is commonly used in fileless execution or stage-one payload delivery by attackers to execute malicious scripts directly from memory.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
709
Detects usage of the net1.exe utility to list members of the local 'Administrators' group in various languages. This technique is often used by adversaries for local system discovery during the reconnaissance phase.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects network traffic directed towards Telegram shortened URLs (t.me) which is a common command-and-control (C2) communication channel used by Vidar and other malware families to exfiltrate data or retrieve instructions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects modifications to the WDigest 'UseLogonCredential' registry key. Enabling this setting (setting it to 1) forces the WDigest SSP to store plaintext credentials in memory, which facilitates easier credential harvesting by attackers using memory dumping techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects potential web shells that employ steganographic techniques by embedding malicious executable script code within image file structures (JPG or PNG). It specifically flags files containing common web shell markers 'ONEPIECE' or 'x_best_911' in combination with embedded script tags (e.g., <script, eval, <%, <?php) within files identified as having image magic bytes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects GitHub OAuth authorization, repository cloning, or ZIP downloads from source IP addresses that have not been observed for the specific actor within the past 30 days. This rule helps identify potential account compromise or token theft where an attacker attempts to access repository data from a new location, while specifically excluding bot/service accounts known for rotating CI infrastructure IPs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
005
Detects the creation or execution of a scheduled task named 'CreateObjectTask' via schtasks or PowerShell, which is associated with spawning 'dllhost.exe' as a child process under high-privileged parent processes (svchost, taskeng, or schtasks). This behavior is indicative of potential COM hijacking or privilege escalation techniques leveraging system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the use of PowerShell to perform COM database enumeration, often associated with OleViewDotNet or NtObjectManager tools, specifically looking for indicators of COM object querying such as InProcServer32 path identification.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects web browser processes (e.g., Chrome, Edge, Firefox) spawned by parent processes that are not typical for web browser execution. This behavior is often associated with malware (such as infostealers) using unconventional process spawning to inject code or perform credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects the use of PowerShell cmdlets often associated with enumerating COM object registrations, specifically targeting 'InProcServer32' registry keys. Such enumeration is a common reconnaissance step for identifying 'dangling' COM objects—registrations that point to missing or non-existent files—which can be exploited to achieve DLL Hijacking or persistence via COM hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the dllhost.exe process, running with SYSTEM privileges, loading a dynamic link library (DLL) from a user-writable path within the ProgramData directory. This behavior is consistent with the abuse of COM marshaling, specifically exploiting dangling CLSID entries to force a privileged COM host process to unmarshal and load an attacker-controlled DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects JavaScript loaders associated with the Exvicy/ErrTraffic campaign. The rule identifies obfuscated code that utilizes atob() for Base64 decoding, single-byte XOR operations, TextDecoder for content processing, and dynamic code execution via 'new Function()'. This pattern is commonly used to inject malicious payloads into compromised WordPress sites.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects outbound HTTP requests to the Telegram Bot API (/sendMessage) which are often used by malware (such as 'Exvicy' or 'Small Sieve') for command and control or exfiltration notification, utilizing the Telegram bot token structure in the URI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a specific bot-cloaking technique used by the Exvicy/ErrTraffic framework, where an actor makes requests to bot-decision endpoints (index.php/white.php) while providing a spoofed 'google.com' Referer header to a non-Google destination host. This technique is often used to facilitate the delivery of fraudulent content (e.g., fake Turnstile/ClickFix pages) while evading detection by security scanners and undesired geographic regions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects outbound network traffic from internal hosts directed toward identified Exvicy command-and-control (C2) infrastructure IP addresses. This includes both general beaconing attempts and established TLS handshake sessions potentially linked to post-ClickFix malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects an attempt to exploit a directive injection vulnerability in the SharePoint 'WebPartPages.asmx' SOAP web service, specifically targeting the 'GetWebPartPageConnectionInfo' method. The rule looks for suspicious 'Register' directives in the request body, which could lead to unauthorized code execution or configuration manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002