Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

This rule monitors for file creation or modification events related to the Admin Menu Editor Pro WordPress plugin, specifically looking for indicators of specific versions (2.35, 2.36) or file naming conventions. It also alerts on network communication to the plugin's domain, which could indicate a compromise or the use of an unauthorized or modified plugin version that may be associated with known vulnerabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
001
Detects DNS resolution requests for the domain 'myaccount.microsoft.com', which is the Microsoft account management portal. This activity is often associated with legitimate user authentication or account configuration processes, but can be used as part of reconnaissance or credential-related activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
001
Detects individual process-level invocations of Microsoft Graph API endpoints commonly used for reconnaissance of user, group, and role information. This rule acts as a precursor signal to identify potential enumeration activities within an Office 365 environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
001
Detects DNS resolution attempts for graph.microsoft.com by processes other than standard web browsers or mail clients. This activity is indicative of scripted tools or malicious software attempting to enumerate or access Microsoft 365 mailbox content via the Graph API, bypassing normal user interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
001
Detects the creation or modification of a scheduled task named 'Maps Performance Task' using schtasks.exe or reg.exe. This task is often associated with legitimate Windows system maintenance related to map data but may be monitored as it involves persistence mechanisms.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
30 days ago
108
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
002
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
002
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
102
This rule identifies critical or high-severity software vulnerabilities affecting devices tagged as part of a PCI-CDE (Payment Card Industry Cardholder Data Environment) scope. It summarizes the findings by CVE, severity level, count of affected devices, and specific assets involved, prioritizing remediation for PCI compliance.
avatar
Ali AlEnezi@site
avatar
Detections.ai Community
25 days ago
102
Detects instances where processes associated with AutoIt scripting (e.g., AutoIt-based compiled executables or scripts) initiate suspicious API calls including CreateRemoteThread, OpenProcess, or generic ProcessInjection against known target binaries such as RegSvcs.exe or mobsync.exe. These binaries are frequently abused for proxy execution or living-off-the-land techniques to hide malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
102
Detects the creation of .lnk files in Windows startup folders combined with the execution of AutoIt automation scripts, a technique commonly used for persistence and malware execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
002
This rule detects the creation of files within the '\Users\Public\' directory that follow a specific, suspicious dynamic naming pattern: 'DeviceName@4AccountName'. Attackers often use the Public directory for staging malicious tools or payloads. This naming convention, which includes both the hostname and the executing account name, is highly indicative of automated, malicious activity or custom staging scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
002
Detects suspicious PowerShell execution initiated by explorer.exe containing encoded commands, correlated with concurrent activity in the Windows RunMRU registry key or execution of rundll32.exe referencing 'WindowsUpdate.log'. This pattern is frequently used to mask malicious activity and maintain stealth during fileless execution or persistence operations.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
508
This rule detects potential command and control (C2) beaconing activity associated with the Casbaneiro (Metamorfo) banking trojan. It looks for instances where a known suspicious process (RegSvcs.exe or mobsync.exe) performs network communication within 5 minutes of a web browser on the same device navigating to a targeted banking URL.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
002
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
2011
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
002
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
002
Detects network connections to known JeetBot infrastructure domains and IP addresses. The rule specifically identifies potential exfiltration of Twitch OAuth tokens via URL parameters or interaction with known token-collection proxy endpoints, which are associated with the JeetBot/Twitch Enhanced Viewer credential harvesting campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
002
Detects network connections to known JeetBot infrastructure domains and IP addresses. The rule specifically identifies potential exfiltration of Twitch OAuth tokens via URL parameters or interaction with known token-collection proxy endpoints, which are associated with the JeetBot/Twitch Enhanced Viewer credential harvesting campaign.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
002
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
002
Detects network connections originating from browser processes to known JeetBot command and control (C2) infrastructure. The rule identifies suspicious C2 communication and, specifically, attempts at token exfiltration by monitoring for auth tokens in the URL of requests directed to known JeetBot hosts and Twitch-related infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
002
Page 331 of 1871