Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule detects HTTP POST requests to Vercel-hosted domains containing suspected phishing telemetry (such as device fingerprinting, keystrokes, and user agent collection) originated from a Google Sites frame. This is a common pattern for phishing kits masquerading as legitimate Ledger service pages to harvest credentials and hardware information.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects unauthorized attempts to extract credentials from the Local Security Authority Subsystem Service (LSASS) process. It monitors for two distinct techniques: non-standard processes opening handles to lsass.exe with sensitive access rights (credential-dumping) and the use of rundll32.exe to invoke the MiniDump function within comsvcs.dll against lsass.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
This rule detects HTTP traffic where a response from a Google Cloud Storage bucket (storage.googleapis.com) initiates a redirect via meta-refresh or JavaScript to a Vercel-hosted domain. This pattern is indicative of phishing infrastructure, where attackers leverage legitimate, trusted storage platforms to redirect users to malicious landing pages.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects HTTP traffic where a response from a Google Cloud Storage bucket (storage.googleapis.com) initiates a redirect via meta-refresh or JavaScript to a Vercel-hosted domain. This pattern is indicative of phishing infrastructure, where attackers leverage legitimate, trusted storage platforms to redirect users to malicious landing pages.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects HTTP traffic where a response from a Google Cloud Storage bucket (storage.googleapis.com) initiates a redirect via meta-refresh or JavaScript to a Vercel-hosted domain. This pattern is indicative of phishing infrastructure, where attackers leverage legitimate, trusted storage platforms to redirect users to malicious landing pages.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects directory replication requests (Event ID 4662) using DS-Replication-Get-Changes or DS-Replication-Get-Changes-All GUIDs initiated by a computer account that is not a recognized domain controller. This behavior is indicative of a DCSync attack, where an adversary attempts to pull sensitive credential data directly from Active Directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects HTTP traffic where a response from a Google Cloud Storage bucket (storage.googleapis.com) initiates a redirect via meta-refresh or JavaScript to a Vercel-hosted domain. This pattern is indicative of phishing infrastructure, where attackers leverage legitimate, trusted storage platforms to redirect users to malicious landing pages.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the execution of the Chisel C2 tool by matching its unique command-line grammar, specifically the 'client' subcommand combined with reverse remote ('R:') configurations. This detection strategy is resilient against binary renaming and infrastructure rotation by focusing on the tool's required argument structure rather than static IOCs like filenames or C2 addresses. It is specifically useful for identifying unauthorized remote tunnels used for persistence and data exfiltration.
avatar
Yougesh Raj@yougesh
avatar
SlimKQL
17 days ago
106
This rule identifies potential RDP-based lateral movement by detecting when a single user account successfully authenticates to multiple distinct hosts using LogonType 10 (RemoteInteractive) within a 1-hour time window. A threshold of three or more distinct hosts is used to flag activity that deviates from typical single-host RDP usage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the use of legitimate Windows binaries (LOLBins) certutil.exe and bitsadmin.exe for suspicious activities such as downloading files via URL or decoding encoded files. This rule explicitly excludes known legitimate administrative activity originating from Microsoft Configuration Manager (SCCM).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the initialization of cloud synchronization tools like rclone or MEGAsync, accompanied by the creation of configuration files and subsequent high-volume network activity directed toward common cloud storage providers, indicative of unauthorized data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects successful user authentications originating from geographically distant locations within a time window that makes physical travel impossible. The detection further filters for scenarios where the subsequent sign-in is associated with a different, non-compliant, or untrusted device, indicating a likely compromised account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects potential credential dumping from the Local Security Authority Subsystem Service (LSASS) memory. It identifies two common techniques: 1) The use of the Windows 'comsvcs.dll' library exported via 'rundll32.exe' to initiate a minidump of the LSASS process, and 2) Unauthorized processes opening handles to LSASS with specific access rights (0x1010, 0x1410) often associated with memory reading for dumping purposes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects potential password spraying activity by identifying high-volume failed authentication attempts (ResultType 50126 or 50053) against multiple accounts from a single source IP, followed by a successful authentication from the same IP. This pattern indicates an adversary who has identified one or more valid credentials after an initial spraying campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects successful user sign-ins from geographically distant locations occurring within a timeframe that is physically impossible to traverse (implied speed > 900 km/h). The rule further filters for scenarios where the device used for authentication appears non-compliant or uses an unrecognized method, potentially indicating an attacker utilizing stolen credentials and bypassing MFA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects rapid, large-scale deletion of Azure storage accounts by a single identity within a short timeframe. This behavior is indicative of destructive activity, such as a malicious actor attempting to disrupt service availability or impact organizational data, rather than typical administrative teardown.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects rapid, large-scale deletion of Azure storage accounts by a single identity within a short timeframe. This behavior is indicative of destructive activity, such as a malicious actor attempting to disrupt service availability or impact organizational data, rather than typical administrative teardown.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects rapid, large-scale deletion of Azure storage accounts by a single identity within a short timeframe. This behavior is indicative of destructive activity, such as a malicious actor attempting to disrupt service availability or impact organizational data, rather than typical administrative teardown.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects rapid, large-scale deletion of Azure storage accounts by a single identity within a short timeframe. This behavior is indicative of destructive activity, such as a malicious actor attempting to disrupt service availability or impact organizational data, rather than typical administrative teardown.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a suspicious sequence of behavior where an Azure service principal authenticates and immediately performs broad reconnaissance (enumeration) across multiple subscriptions and resource types. This pattern is often indicative of an adversary using a compromised service principal credential to map out an environment.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a suspicious sequence of behavior where an Azure service principal authenticates and immediately performs broad reconnaissance (enumeration) across multiple subscriptions and resource types. This pattern is often indicative of an adversary using a compromised service principal credential to map out an environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000