Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
004
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
204
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
004
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
104
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
004
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
004
This rule detects modifications to Group Policy Objects (GPO) or Microsoft Entra (formerly Azure AD) policies that weaken established security controls. For GPO, it monitors Event ID 5136 for changes to security-relevant attributes (e.g., disabling firewall or real-time monitoring) in Active Directory. For Entra, it monitors audit logs for administrative operations that reduce security posture, such as disabling MFA, lowering authentication trust, or deleting Conditional Access policies. It includes filters to exclude legitimate, documented change management activities.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
104
Detects Run key persistence pointing to the known VBScript staging directory (C:\Users\Public\Libraries\Default\Lib\Lib1) used by the worm-like ScreenConnect campaign (Aug 2026), matching known script filenames (WindowsServiceHost.vbs, 1.vbs-4.vbs) invoked via wscript.exe/cscript.exe.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
004
Detects suspicious PowerShell execution initiated by explorer.exe containing encoded commands, correlated with concurrent activity in the Windows RunMRU registry key or execution of rundll32.exe referencing 'WindowsUpdate.log'. This pattern is frequently used to mask malicious activity and maintain stealth during fileless execution or persistence operations.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
104
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
204
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
204
Detects the execution of known malicious files associated with the BlueDelta threat group, specifically the HOOKEDGE and HEADLACE malware families, using a curated list of SHA-256 file hashes. Additionally, the rule monitors for the execution of scripts with GUID-based filenames, a common tactic for temporal or staged file deployment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
003
Matches known HOOKEDGE malware samples attributed to BlueDelta (APT28) via SHA256 hash comparison
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
003
Matches known HOOKEDGE malware samples attributed to BlueDelta (APT28) via SHA256 hash comparison
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
003
Detects network communication with Google Sheets API endpoints that contain specific indicators of C2 behavior, such as suspicious User-Agents, specific spreadsheet cell references, or input options characteristic of automated data exfiltration or command retrieval.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
5012
This rule monitors for outbound network connections to a list of known malicious IP addresses identified as part of the GhostCode command-and-control (C2) infrastructure. It uses DeviceNetworkEvents data to flag activity originating from endpoints and highlights a specific IP address used during the Intune/MDM enrollment process for further investigation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
001
Detects network activity and HTTP request headers associated with the GhostCode phishing kit. The rule identifies specific URI patterns, custom site keys, malicious User-Agent strings, and session cookie artifacts indicative of interaction with a phishing server.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
001
Detects instances of ImageMagick binaries (convert, identify, magick) spawning suspicious child processes (e.g., shells, network tools, scripting interpreters) when processing image files with HEIF/HEIC extensions. This is a common pattern for exploiting image processing vulnerabilities (e.g., ImageTragick) to achieve remote code execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
000
Detects instances of ImageMagick binaries (convert, identify, magick) spawning suspicious child processes (e.g., shells, network tools, scripting interpreters) when processing image files with HEIF/HEIC extensions. This is a common pattern for exploiting image processing vulnerabilities (e.g., ImageTragick) to achieve remote code execution.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
000
Detects instances of ImageMagick binaries (convert, identify, magick) spawning suspicious child processes (e.g., shells, network tools, scripting interpreters) when processing image files with HEIF/HEIC extensions. This is a common pattern for exploiting image processing vulnerabilities (e.g., ImageTragick) to achieve remote code execution.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
000
Detects instances of ImageMagick binaries (convert, identify, magick) spawning suspicious child processes (e.g., shells, network tools, scripting interpreters) when processing image files with HEIF/HEIC extensions. This is a common pattern for exploiting image processing vulnerabilities (e.g., ImageTragick) to achieve remote code execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
000
Page 323 of 1871