Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors for outbound network connections to a list of known malicious IP addresses identified as part of the GhostCode command-and-control (C2) infrastructure. It uses DeviceNetworkEvents data to flag activity originating from endpoints and highlights a specific IP address used during the Intune/MDM enrollment process for further investigation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
This rule detects internal network activity (DNS queries, network connections, and security logs) communicating with domains associated with the GhostCode phishing kit. These domains are typically used to host credential harvesting pages or phishing infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects network activity and HTTP request headers associated with the GhostCode phishing kit. The rule identifies specific URI patterns, custom site keys, malicious User-Agent strings, and session cookie artifacts indicative of interaction with a phishing server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects various methods and tools used by adversaries to access, stage, or exfiltrate the Active Directory database (ntds.dit). This includes abuse of built-in Windows utilities such as ntdsutil, vssadmin, diskshadow, esentutl, and registry commands, as well as the use of known credential dumping tools like Impacket's SecretsDump and NinjaCopy.
avatar
Gaurav Thakare@gauravthakare
avatar
Detections.ai Community
1 month ago
14015
This rule detects instances where a Kerberos Service Ticket (TGS, Event ID 4769) is requested without a corresponding TGT request (AS-REQ, Event ID 4768) from the same user and IP address within a 10-hour window. This behavior is indicative of potential Kerberoasting, where an attacker may have obtained TGS tickets using cached or manually constructed credentials rather than through the normal authentication flow.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
005
This rule detects network communication, email interaction, or identity logon events related to known spoofed IC3 (Internet Crime Complaint Center) domains used in business email compromise (BEC) campaigns. The detection covers multiple telemetry sources including email URL information, device network events, and identity logon logs to identify attempts to interact with fraudulent portals.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
27 days ago
204
Detects the execution of known remote monitoring and management (RMM) software often abused by threat actors following social engineering attempts, such as helpdesk impersonation, to establish persistence and remote access prior to deploying ransomware.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
1 month ago
009
Extracts LDAP search queries from Microsoft-Windows-LDAP-Client Event ID 30 logs on endpoints. Accepts hostname, username, or IP as input. Shows initiating process with full command line, search filter, base DN, and requested attributes. Good for triaging LDAP enumeration alerts and identifying whether queries come from known AD tools or suspicious recon activity.
avatar
chiki briki@ekkor13
avatar
Detections.ai Community
1 month ago
26034
Detects the modification or creation of registry entries in the 'RunOnce' hive that attempt to execute 'RuntimeBroker.exe' from suspicious or non-standard locations such as 'AppData' or 'MyData'. This behavior is characteristic of an adversary attempting to maintain persistence by masquerading as a legitimate Windows system process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects the loading of 'libcurl.dll' or related DLL patterns from suspicious directories such as '\Microsoft\Crypto\RuntimeBroker\', often associated with process masquerading or side-loading activities. The rule also monitors for the execution of suspicious binaries ('Tax_Notice_45594.exe') or binaries that mimic 'Notepad++' metadata from within these paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects instances where cvtres.exe performs suspicious actions such as ProcessInjected, CreateRemoteThread, or OpenProcessApiCall, excluding known legitimate development and build tool contexts. This activity is highly anomalous as cvtres.exe is a resource object converter and should not be interacting with the memory of other processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects activity where potential staging files (e.g., .dat or .dll files with specific naming patterns) are created or accessed within suspicious directories like AppData or RuntimeBroker folders, followed by the execution or loading of 'libcurl.dll'. This pattern is indicative of a loader or malware component staging its payload before using a network library to communicate with an external server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects the execution of known PAPERMILL/VenomRAT loader samples, identified by specific suspicious file names. The detection monitors for the initiation of these processes, followed by a delayed (5-10 minutes) creation of RunOnce registry persistence entries that masquerade as RuntimeBroker.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects outbound network connections to 'acrobat-updater.com' involving suspicious API paths that mimic the Adobe Acrobat updater. This may indicate an attempt by an adversary to masquerade malicious command and control or data exfiltration as legitimate update traffic.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
23 days ago
001
Detects the execution or invocation of processes matching a known list of malicious file hashes (SHA256). The rule monitors both direct execution (SHA256) and instances where a malicious file acts as an initiating process.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
001
Detects the execution or invocation of processes matching a known list of malicious file hashes (SHA256). The rule monitors both direct execution (SHA256) and instances where a malicious file acts as an initiating process.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
001
Detects execution or file presence of known malicious files based on a pre-defined list of SHA256 hashes associated with known threat activity.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
23 days ago
001
Detects execution or file presence of known malicious files based on a pre-defined list of SHA256 hashes associated with known threat activity.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
001
This rule detects outbound network connections from internal devices to a list of known malicious IP addresses associated with adversary command and control infrastructure. The rule specifically monitors connections over common ports, potentially indicating established communication with malicious servers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects outbound network connections to specific disposable Cloudflare workers.dev subdomains identified as part of the KREMLIN (REF9334) C2 infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects outbound network connections to 'acrobat-updater.com' involving suspicious API paths that mimic the Adobe Acrobat updater. This may indicate an attempt by an adversary to masquerade malicious command and control or data exfiltration as legitimate update traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Page 324 of 1871