Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects the execution of the SentinelOne memory scanner process (SentinelMemoryScanner.exe) or the loading of the associated SentinelOne core library (SentinelAgentCore.dll) from a directory path outside of the standard SentinelOne installation locations (Program Files\SentinelOne or Program Files (x86)\SentinelOne). This behavior is indicative of potential masquerading or tampering where an adversary attempts to execute a renamed or moved security tool to bypass policy or evade detection.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
1009
Detects the use of PowerShell cmdlets such as Invoke-WmiMethod, Invoke-CimMethod, Get-CimInstance, or Get-WmiObject to interact with the Win32_Process class for process creation on local or remote systems. This behavior is frequently associated with administrative activity but is also commonly used by adversaries for remote command execution and lateral movement.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
105
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
205
Detects the use of Dumpert process dumper, which dumps the lsass.exe process memory
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
23 days ago
001
Detects the execution of batch files named 'db.bat' or 'adb.bat' from the Windows User Temp directory using cmd.exe. This activity is a known indicator of the OpnKey ransomware, which utilizes these scripts to facilitate its operations.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
102
Detects the use of net.exe to stop critical system services commonly associated with ransomware operations, such as volume shadow copies, security services, and Windows update services, to facilitate data encryption or prevent system recovery.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
002
Detects the use of the Windows schtasks utility to delete a scheduled task named 'Windows Update'. This pattern is associated with OpnKey ransomware, which attempts to remove legitimate or potentially competing tasks to maintain persistence or avoid detection.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
002
Detects the deletion of a file named 'Config.ini', a behavior associated with the OpnKey ransomware for cleaning up configuration artifacts after its execution cycle.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
102
Detects the presence of OpnKey ransomware-specific configuration strings related to size-tiered file encryption settings in process command lines. These indicators suggest the execution of a binary with hardcoded logic to categorize files for encryption based on their size.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
002
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
8012
Detects high-volume usage of SAMR RPC functions (SamrEnumerateUsersInDomain, SamrLookupNamesInDomain, SamrQueryInformationUser) used to enumerate domain users and account attributes. This behavior is indicative of reconnaissance activities performed by tools such as secretsdump, BloodHound, and NetExec.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
29 days ago
3405
Page 334 of 1871