Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects a high volume of unique command executions within a short time window where the command lines contain patterns resembling developer or script comments (e.g., # or // followed by keywords like 'attempt', 'retry', 'diagnos'). The threshold-based logic (over 600 unique commands in less than 1 hour) combined with high-frequency retry attempts suggests automated or scripted activity, potentially indicative of automated exploitation frameworks, reconnaissance, or brute-force tools that include verbose logging or internal notes within the command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the use of the Rubeus tool for Kerberos-based credential attacks, specifically Kerberoasting, TGT delegation abuse, and Pass the Ticket, by monitoring process command line arguments for characteristic flags associated with the Rubeus binary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects a suspicious correlation where a host reports a confirmed exploit attempt followed by a high volume of file modifications (encryption behavior) within a single hour. This short dwell time is a strong indicator of automated or AI-orchestrated ransomware deployments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects unauthorized directory replication requests (DRSGetNCChanges or DRSReplicaSync) originating from a host that is not identified as a Domain Controller. This behavior is indicative of a DCSync attack, where an adversary impersonates a domain controller to extract credential hashes from the Active Directory database.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects command-line activity associated with Monkey ransomware, specifically attempts to bypass AMSI (patching AmsiScanBuffer, targeting AmsiUtils), disable ETW (Event Tracing for Windows) monitoring, and add Microsoft Defender exclusions to evade detection prior to encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the creation of a 'config.ini' file within the 'UBP-Asset' directory, correlated with subsequent FTP network activity from known associated binaries (UBPUpdater.exe, UBPPatch.Psh, cmd.exe, or UBP.exe). This behavioral pattern is indicative of Quasar RAT being delivered or updated through a fraudulent install path.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
Detects the creation of a 'config.ini' file within the 'UBP-Asset' directory, correlated with subsequent FTP network activity from known associated binaries (UBPUpdater.exe, UBPPatch.Psh, cmd.exe, or UBP.exe). This behavioral pattern is indicative of Quasar RAT being delivered or updated through a fraudulent install path.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
000
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
This rule detects potential ransomware activity by monitoring for a high volume (more than 10) of file creation or renaming events within a short timeframe (30 minutes) initiated by a process named 'htspnew.exe'. It excludes common system and temporary directories to reduce noise, focusing on suspicious file modifications that might indicate bulk encryption or mass file manipulation.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
This rule detects potential ransomware activity by monitoring for a high volume (more than 10) of file creation or renaming events within a short timeframe (30 minutes) initiated by a process named 'htspnew.exe'. It excludes common system and temporary directories to reduce noise, focusing on suspicious file modifications that might indicate bulk encryption or mass file manipulation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
This rule detects potential ransomware activity by monitoring for a high volume (more than 10) of file creation or renaming events within a short timeframe (30 minutes) initiated by a process named 'htspnew.exe'. It excludes common system and temporary directories to reduce noise, focusing on suspicious file modifications that might indicate bulk encryption or mass file manipulation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
000
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
Detects the execution of common Windows command-line tools (such as cmd, powershell, or wmic) being used to query system information related to security configurations, antivirus status, firewall status, or installed security products. This behavior is indicative of an adversary performing reconnaissance to understand the defensive landscape of a compromised host.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
4024
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
005
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
005
Detects the execution of AutoIt3 scripts using mshta.exe as the parent process from suspicious or non-standard directories such as Temp, Downloads, or AppData. This behavior is indicative of an attempt to bypass application execution policies or obfuscate malicious script execution.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
Detects the execution of AutoIt3 scripts using mshta.exe as the parent process from suspicious or non-standard directories such as Temp, Downloads, or AppData. This behavior is indicative of an attempt to bypass application execution policies or obfuscate malicious script execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
Detects the execution of AutoIt3 scripts using mshta.exe as the parent process from suspicious or non-standard directories such as Temp, Downloads, or AppData. This behavior is indicative of an attempt to bypass application execution policies or obfuscate malicious script execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
Page 314 of 1871