Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects potential DLL side-loading activity by identifying when known malicious file hashes are loaded by a specific set of executable files that are commonly abused for side-loading, or when these executables are executed from locations outside of their standard, verified installation directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
001
This rule monitors network connection logs, DNS query logs, and common security logs for known indicators of compromise, specifically IP addresses and domains associated with command and control (C2) infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
001
This rule detects potential credential dumping attempts targeting the Local Security Authority Subsystem Service (LSASS) process. It identifies suspicious file execution based on a blocklist of known credential dumping utility hashes, unauthorized OpenProcess calls to lsass.exe with specific access rights, and the creation of process memory dump files (e.g., .dmp, .dump) correlated with an lsass.exe access event.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
001
Detects indicators of the FamousSparrow threat actor, including the creation of known malicious files (e.g., DotNetNuke.ashx, start.bat), unauthorized .ashx file writes in web application directories, and suspicious command execution chains (start.bat execution or w3wp.exe spawning command-line utilities) following the creation of .ashx files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
001
Detects the execution of command-line tools (powershell, cmd, bash, curl, etc.) originating from common package managers and build tools (npm, node, pip, python, yarn). The rule flags these processes if they contain command-line arguments indicative of suspicious activity such as base64-encoded commands, remote script execution (IEX, curl/wget to shell), or indicators of persistence mechanisms (scheduled tasks, registry Run keys).
avatar
Ali AlEnezi@site
avatar
Detections.ai Community
24 days ago
102
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
2013
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
2011
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
005
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
205
Detects the use of the native Windows utility 'wbadmin.exe' to delete the system backup catalog or system state backups. This activity is a common indicator of ransomware or other destructive attacks aiming to inhibit system recovery by preventing administrators from restoring data from existing backups.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
003
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
005
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
105
This KQL detects potential social engineering and vishing activity in Microsoft Teams over the last 30 days.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
1 month ago
24066
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
408
Detects remote service manipulation, including service creation, starting, and deletion, using the SVCCTL RPC interface. This activity is a common method for lateral movement and remote code execution by tools like PsExec, smbexec, and CrackMapExec.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
29 days ago
207
This rule detects potentially suspicious file deletion activity originating from PowerShell processes (powershell.exe or pwsh.exe). It monitors for commands targeting temporary directories and specific file extensions (such as .vbs, .lnk, .js, or .ps1) combined with recursive deletion arguments. Additionally, it highlights scenarios where these PowerShell commands are executed by potentially unusual parent processes such as script engines (wscript.exe, cscript.exe, mshta.exe) or other command-line utilities.
avatar
F S@Fsdr
avatar
Detections.ai Community
28 days ago
406
Detects high-frequency file creation, opening, or modification events within the Windows AppData Local Temp directory. This behavior, often involving specific obfuscated file names or known malicious process names, is a common indicator of malware payload staging or execution patterns, such as those observed in AsyncRAT infections.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
002
Detects the execution of the Windows Character Map utility (charmap.exe) when launched from a user-writable Temp directory by a non-standard parent process. This pattern is commonly associated with malware, such as AsyncRAT, attempting to leverage legitimate system tools to evade detection or facilitate malicious chains.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
002
Detects instances where the Windows Character Map utility (charmap.exe) loads both 'amsi.dll' (Antimalware Scan Interface) and 'clr.dll' (Common Language Runtime). This combination is highly anomalous for charmap.exe and is indicative of process injection or defense evasion attempts, often associated with executing arbitrary malicious code within a trusted system process.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
002
Page 319 of 1871