Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the presence of references to the gdrv.sys driver within files or command-line strings. The gdrv.sys driver is a known vulnerable driver frequently exploited in Bring Your Own Vulnerable Driver (BYOVD) attacks to gain kernel-mode privileges and disable endpoint security products.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects unauthorized processes attempting to access sensitive browser files, specifically 'Login Data' (credentials) and 'Network/Cookies' databases for Google Chrome and Microsoft Edge. Legitimate browser processes and update services are explicitly excluded.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects the use of the wevtutil.exe utility to clear specific Windows Event Logs. Adversaries may clear event logs to hide evidence of malicious activity on a system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects the use of PowerShell to load .NET assemblies directly from memory or via Base64/encoded streams. This technique is commonly used by malicious payloads to execute shellcode, reflection-based attacks, or obfuscated scripts while minimizing their on-disk footprint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects the creation of files with specific extensions (.locked, .locked_wip) or filenames (RESTORE_FILES.txt) commonly associated with ransomware operations and ransom notes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects instances where AI-assisted coding tools or command-line interfaces spawn scripting runtimes (Node.js, Python) to access sensitive files such as SSH keys, cloud provider credentials, or Kubernetes configurations. This behavior may indicate an AI coding assistant being coerced or misconfigured to exfiltrate secrets from the development environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects instances where AI-assisted coding tools (Claude, GitHub Copilot, Codex) spawn the git process to perform a specific 'checkout' command followed by a full commit hash. This behavior may indicate an automated or malicious attempt to manipulate repository states, inject code, or perform unauthorized checkout operations via an AI-assisted development workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects the execution of Git repository operations (clone, fetch, pull, checkout) initiated by AI-assisted coding tools such as Claude Code, GitHub Copilot, or Gemini CLI. The rule specifically excludes interactive operations, identifying automated or scripted usage of these tools to interact with code repositories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
This rule detects the loading of specific drivers identified as potentially associated with security software evasion or 'Bring Your Own Vulnerable Driver' (BYOVD) tactics, followed by suspicious process termination activity (e.g., termination of security-related processes or system-critical process activity) within a 15-minute window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects the creation or modification of specific system driver files (nvfsflt64.sys, Alinubx.sys) combined with the installation or initiation of a Windows service associated with NVIDIA filter names. This behavior is often indicative of persistence mechanisms, potential rootkit activity, or the deployment of vulnerable drivers (BYOVD).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects instances where sensitive Active Directory database files (NTDS.DIT) are accessed, correlated with the execution of common system administration utilities (ntdsutil, vssadmin, diskshadow, esentutl) known to be leveraged by adversaries to create volume shadow copies or extract data for offline credential harvesting.
avatar
Gaurav Thakare@gauravthakare
avatar
Detections.ai Community
1 month ago
4112
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
4018
Detects instances where Windows Filtering Platform (WFP) has blocked outbound network connections initiated by critical Microsoft Defender components (e.g., MsSense.exe, MsMpEng.exe). Such blocks may indicate security software interference, misconfiguration, or attempts to disrupt endpoint security monitoring.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
7029
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Page 336 of 1870