Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
Detects the creation of a new Windows service where the service executable is located in potentially suspicious directories such as \Temp\, \Users\Public\, \AppData\, or \ProgramData\. Attackers often use these locations to drop and execute malicious payloads or persistence mechanisms while bypassing standard software installation security controls.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
8 days ago
101
This rule detects the connection of USB devices that are commonly used to emulate keyboards or mouse inputs for malicious purposes, such as BadUSB, Rubber Ducky, Arduino, or Teensy devices. These devices can be used to deliver keystroke injection attacks to bypass security controls.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
8 days ago
101
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
avatar
Arnold Chan@slaz
avatar
SlimKQL
16 days ago
4012
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
2010
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
106
Detects anomalous child process execution (e.g., cmd.exe, powershell.exe) by the Microsoft Exchange IIS worker process (w3wp.exe) or the creation of .aspx files in Exchange web directories. This behavior is highly indicative of post-exploitation activity, such as web shell deployment, frequently observed in attacks targeting vulnerabilities like ProxyShell and ProxyLogon.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
007
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
102
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
102
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
202
Detects a file named dnsapi.dll created/modified outside System32/SysWOW64/WinSxS (the only legitimate locations for the real system DLL). Now requires the file to BOTH land in one of the known NeedyMantis sideload staging folders AND match the published 3448-byte spoofed-config size -- previously the size check alone could match unrelated dnsapi.dll copies anywhere on disk; requiring both signals together removes that bypass.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
002
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
002
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
002
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
002
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
003
Detects an exploitation chain originating from a Chrome browser process, characterized by the execution of an anomalous child process followed by the creation of an executable file named 'chrome_cleanup.exe' within a short time window. This sequence is indicative of multi-stage exploitation, involving remote code execution via browser vulnerability and subsequent privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
3012
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
4018
This rule detects potential credential stuffing attacks by monitoring high-volume authentication attempts against web application login endpoints. It specifically flags scenarios where a high number of unique source IP addresses interact with a login endpoint (e.g., /login, /signin) within a short window, which is characteristic of automated, distributed credential stuffing tools using proxy networks to rotate IPs.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects HTTP requests containing common web exploit patterns (SQLi, XSS, RCE) that exhibit characteristics of automated, mutating payload generation often utilized in AI-assisted fuzzing or vulnerability scanning tools. The rule monitors for encoded, obfuscated, or highly varied payload syntax within URI query strings.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects anomalous outbound lateral movement attempts where a single source host initiates WinRM connections (ports 5985/5986) to an unusually high number of distinct destination hosts within a short timeframe, which is often indicative of automated credential propagation or internal scanning by an adversary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
This rule detects a high frequency of SMB (port 445) connection attempts from a single internal source host to a large number of distinct internal destination hosts within a short timespan. This activity is indicative of internal network scanning, host discovery, or automated lateral movement attempts using SMB.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
Page 33 of 1866