Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects either the presence of known malicious image files (based on SHA256 hashes) on a device or network connection attempts to known malicious URLs hosting such files. This pattern is commonly associated with steganographic techniques used to hide malicious payloads within image files for C2 or delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
This rule detects network connections to a list of known lookalike domains or specific indicators (a payload GUID and a URI hash) associated with suspicious activity. It uses a time-based aggregation to identify hosts interacting with multiple suspicious domains or both specific payload indicators, suggesting potential C2 activity or a targeted phishing/malware delivery campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
This rule monitors network connections and HTTP requests for specific URL patterns that include encoded (base64) parameters and indicators often associated with command and control or data exfiltration. It detects endpoints accessing URLs containing a prefix sequence of 10 characters and specific endpoints like '/generate' or '/kremlin'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
This rule monitors for process execution and file activity associated with a specific file hash known to be malicious. By tracking both process and file events using a SHA256 identifier, it captures when a specific threat artifact is executed or interacted with on a system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
This rule monitors for the execution of a process that matches a specific SHA256 file hash identified as malicious.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
This rule detects the presence or execution of a specific CAB file identified by its SHA256 hash. It monitors both file creation/access events and process execution events involving this hash, indicating potential malicious activity involving a known malicious cabinet file.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects the execution or invocation of processes matching a known list of malicious file hashes (SHA256). The rule monitors both direct execution (SHA256) and instances where a malicious file acts as an initiating process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects execution or file presence of known malicious files based on a pre-defined list of SHA256 hashes associated with known threat activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
309
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
909
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
1709
This rule identifies developer or contractor workstations that have Node.js/npm installed but currently lack active EDR sensor coverage (i.e., the sensor is either not onboarded or not in an active state). It employs a 24-hour grace period to filter out transient onboarding issues and ensures that the device has reported activity within the last 7 days to avoid alerting on decommissioned hardware. This gap in visibility increases the risk of undetected supply-chain malware execution and credential theft on sensitive developer endpoints.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
000
This rule identifies developer or contractor workstations that have Node.js/npm installed but currently lack active EDR sensor coverage (i.e., the sensor is either not onboarded or not in an active state). It employs a 24-hour grace period to filter out transient onboarding issues and ensures that the device has reported activity within the last 7 days to avoid alerting on decommissioned hardware. This gap in visibility increases the risk of undetected supply-chain malware execution and credential theft on sensitive developer endpoints.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
000
This rule identifies developer or contractor workstations that have Node.js/npm installed but currently lack active EDR sensor coverage (i.e., the sensor is either not onboarded or not in an active state). It employs a 24-hour grace period to filter out transient onboarding issues and ensures that the device has reported activity within the last 7 days to avoid alerting on decommissioned hardware. This gap in visibility increases the risk of undetected supply-chain malware execution and credential theft on sensitive developer endpoints.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
000
This rule identifies developer or contractor workstations that have Node.js/npm installed but currently lack active EDR sensor coverage (i.e., the sensor is either not onboarded or not in an active state). It employs a 24-hour grace period to filter out transient onboarding issues and ensures that the device has reported activity within the last 7 days to avoid alerting on decommissioned hardware. This gap in visibility increases the risk of undetected supply-chain malware execution and credential theft on sensitive developer endpoints.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
000
Detects unexpected crashes or restarts of the Windows Defender service (MsMpEng.exe) occurring in temporal proximity to activities associated with the ShieldCrash PoC or tampering within the Windows Defender object manager namespace. This rule aims to identify potential exploitation attempts targeting Windows Defender, specifically correlating security service instability with known malicious indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
1209
This rule detects suspicious activity involving the creation of scheduled tasks for persistence using command-line arguments indicative of tool execution (e.g., chisel, powershell) or the direct execution of hidden PowerShell scripts intended to bypass execution policy.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
This rule detects suspicious activity involving the creation of scheduled tasks for persistence using command-line arguments indicative of tool execution (e.g., chisel, powershell) or the direct execution of hidden PowerShell scripts intended to bypass execution policy.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects Java-based Metasploit/Meterpreter payload files (.class/.jar) dropped post-exploitation, as observed following PaperCut RCE exploitation chain
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
003
Detects GhostContainer .NET-based backdoor assembly components deployed on compromised Exchange servers, requiring multiple corroborating unique indicators (module/class names, C2 header, masquerading filenames) to reduce false positives on generic .NET assemblies
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects GhostContainer .NET-based backdoor assembly components deployed on compromised Exchange servers, requiring multiple corroborating unique indicators (module/class names, C2 header, masquerading filenames) to reduce false positives on generic .NET assemblies
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
Page 325 of 1871