Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects rapid mass-cloning or downloading of private GitHub repositories shortly after an OAuth token authorization, originating from IP addresses or countries not previously associated with the user account. This behavior is indicative of unauthorized bulk data extraction using compromised credentials, consistent with threat actor activity (e.g., TeamPCP/UNC6780).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
005
Detects instances where a removed GitHub organization member performed bulk repository access (cloning or downloading) shortly before their removal, potentially indicating exploitation of retained access by a departed employee or an adversary using a valid account before deprovisioning. The rule identifies activity occurring more than 24 hours prior to removal involving multiple repositories or multiple access actions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
005
Detects the execution of PowerShell with suspicious command-line arguments often used by adversaries for obfuscation, evasion, or in-memory code execution, such as encoded commands, hidden windows, and downloading external content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos Service Ticket (TGS) requests (event ID 4769) for non-machine service accounts, specifically focusing on tickets encrypted with RC4 (etype 23). A high count of ticket requests or distinct Service Principal Names (SPNs) requested by a single client in a short period is characteristic of an adversary attempting to harvest hashes for offline cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects the use of native Windows utilities certutil.exe and bitsadmin.exe for potentially malicious purposes. Specifically, it flags certutil.exe being used for decoding or cached URL operations, and bitsadmin.exe being used to initiate file transfers from remote URLs or network paths. These tools are commonly abused by attackers for file staging, ingress tool transfer, and deobfuscation of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
This rule detects the creation of named pipes with names patterns commonly associated with post-exploitation frameworks, such as Cobalt Strike and Sliver. These frameworks frequently use specific, sometimes randomized, pipe patterns for inter-process communication, lateral movement, or command and control (C2) operations. Monitoring these pipe names can help identify malicious activity occurring within a compromised environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects outbound HTTP requests to the Telegram Bot API associated with the malicious 'indexed-btree' npm package. The rule specifically monitors for hardcoded Telegram bot tokens and chat IDs used for data exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
003
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
001
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
001
Detects an account takeover chain where a device loads a malicious JavaScript component ('load-addon.js') in a browser session, followed by repeated attempts to bypass bot detection mechanisms (targeting Google's 'errors/robot.png') as the payload attempts to force authentication challenges or password resets.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
Detects an account takeover chain where a device loads a malicious JavaScript component ('load-addon.js') in a browser session, followed by repeated attempts to bypass bot detection mechanisms (targeting Google's 'errors/robot.png') as the payload attempts to force authentication challenges or password resets.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
001
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001