Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
401
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects Kerberos TGT or TGS requests that either exhibit a suspicious combination of ticket flags (Forwardable + Proxiable + Renewable) when associated with high-value targets, unusual accounts, or off-hours activity, or utilize the weak RC4-HMAC encryption type, both of which are indicative of ticket manipulation and credential theft.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Detects the use of netsh.exe to establish a port proxy, specifically conditioned on the execution context of the Impacket atexec tool (indicated by specific naming patterns and parent processes). This activity often follows the lateral movement or execution of a remote service by a tool like Impacket.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Page 326 of 1871