Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects the creation of mailbox inbox rules (New-InboxRule) or modification of mailbox forwarding configurations (Set-Mailbox) that auto-forward, auto-delete, or move messages to hidden or secondary folders (e.g., RSS, Deleted Items). This behavior is characteristic of Business Email Compromise (BEC) follow-on activity intended to maintain covert access to victim communications, particularly following account takeover events like password resets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects a suspicious pattern where an inbound Microsoft Teams call or chat from an untrusted external guest tenant is followed within 30 minutes by a credential, MFA, or account-recovery action on the target user's account in Entra ID. This behavior is indicative of a vishing-over-Teams attack where an adversary impersonates IT support to facilitate unauthorized account recovery or MFA bypass.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects instances where processes (excluding known legitimate .NET processes) load common .NET runtime modules (e.g., clr.dll, mscoree.dll) followed by remote process injection or handle-based process access, which is often indicative of reflective assembly loading used by loaders like PIVOTPIPE to execute malicious code within a target process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects a suspicious sequence of events where a user modifies their MFA phone number, followed within 30 minutes by a sign-in event flagged with 'impossibleTravel' or 'unfamiliarFeatures' risk. This pattern is indicative of potential SIM-swap fraud, where an attacker has hijacked the user's phone number to receive MFA prompts and then attempts to access the account from an anomalous location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule monitors for network DNS queries containing keywords commonly associated with credential harvesting and identity verification lures, such as 'sso', 'mfa', 'passkey', or 'helpdesk'. It detects attempts to reach suspicious domains that may be used in phishing campaigns targeting corporate identity portals.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
007
Detects a Node.js server process (e.g. "next-server", "node.exe") spawning
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
007
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
203
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
103
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
103
This rule detects unauthorized attempts to perform a DCSync attack by monitoring for Active Directory Event ID 4662. It triggers when an account that is not a recognized domain controller (which typically end with a '$' sign) successfully requests replication data using the Directory Replication Service (DRS) GetNCChanges rights. This behavior is a common indicator of credential dumping via tools like Mimikatz.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the execution of known privilege escalation tools and the use of specific Windows privilege keywords (such as SeImpersonatePrivilege) often associated with access token manipulation and token impersonation attacks to elevate privileges to SYSTEM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects anomalous DNS traffic patterns indicative of command-and-control (C2) or data exfiltration over the DNS protocol. The rule identifies suspicious queries containing long, high-entropy subdomain labels that suggest payload encoding, as well as the use of TXT records for unauthorized data transmission.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects attempts to disable Windows Defender features via PowerShell, terminate critical security services using administrative tools like sc.exe or net.exe, or inject/patch AMSI (Antimalware Scan Interface) within a process context to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects outbound web or proxy connections to known consumer-grade cloud storage and file-sharing services. This activity is often indicative of data exfiltration, where an adversary uploads staged or archived sensitive data to third-party file hosting services (e.g., Mega, Dropbox, transfer.sh, pastebin) to bypass traditional enterprise exfiltration controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects potentially suspicious activity within a Git repository environment, specifically monitoring for code pushes, administrative changes (such as added collaborators, permission changes, or ownership transfers), and force push operations. It identifies high-impact repository modifications that could indicate unauthorized access, persistence, or attempts to disrupt repository integrity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
006
This rule detects Terraform CLI activity interacting with suspicious domains or modules, specifically targeting known repositories or namespaces (e.g., gocommunity.io, gogets.dev). It monitors for Terraform initialization or application patterns referencing these domains in process command lines, as well as the creation of Terraform provider files within these specific namespaces. This behavior is indicative of potential supply chain compromise involving malicious Terraform modules or dependencies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
201
Detects the execution of 'go' or 'go.exe' with 'run' commands originating from infrastructure automation or orchestration tools such as Terraform, Docker, or other related automation processes. This pattern may indicate the execution of arbitrary Go code or modules in environments where infrastructure code is being managed or deployed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects a single developer identity performing a high volume of git push or clone operations across a large number of distinct repositories within a short timeframe. This behavior is indicative of a compromised developer account being used to programmatically inject code into multiple repositories, potentially for a supply chain attack or mass payload propagation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the execution of terraform.exe or go.exe on developer hosts, which acts as a precursor to the malicious Terraform provider campaign (Graphalgo) that targets cloud credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects suspicious activities associated with ysoserial.net gadget chain exploitation targeting SharePoint's w3wp.exe process. The rule correlates the loading of specific .NET assemblies (PresentationFramework, System.Xaml, System.Data.Services) with the subsequent execution of command shells (cmd, powershell) or the presence of common ysoserial.net-related strings (ActivitySurrogateSelector, LosFormatter) within command lines originating from the w3wp.exe process, indicating a potential web shell.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
002
Detects the execution of the Graphalgo RAT second-stage payload. The rule identifies the spawning of a detached 'go run .' process, which performs an ephemeral key exchange using a hardcoded public key before C2 establishment. It also correlates this activity with parent processes common in software build environments (npm, terraform, go) to differentiate malicious staging from developer activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101