Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
This rule detects the loading of specific drivers identified as potentially associated with security software evasion or 'Bring Your Own Vulnerable Driver' (BYOVD) tactics, followed by suspicious process termination activity (e.g., termination of security-related processes or system-critical process activity) within a 15-minute window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects the creation or modification of specific system driver files (nvfsflt64.sys, Alinubx.sys) combined with the installation or initiation of a Windows service associated with NVIDIA filter names. This behavior is often indicative of persistence mechanisms, potential rootkit activity, or the deployment of vulnerable drivers (BYOVD).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects instances where sensitive Active Directory database files (NTDS.DIT) are accessed, correlated with the execution of common system administration utilities (ntdsutil, vssadmin, diskshadow, esentutl) known to be leveraged by adversaries to create volume shadow copies or extract data for offline credential harvesting.
avatar
Gaurav Thakare@gauravthakare
avatar
Detections.ai Community
1 month ago
4112
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
4018
Detects instances where Windows Filtering Platform (WFP) has blocked outbound network connections initiated by critical Microsoft Defender components (e.g., MsSense.exe, MsMpEng.exe). Such blocks may indicate security software interference, misconfiguration, or attempts to disrupt endpoint security monitoring.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
7029
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects execution and file artifacts associated with the 'fscan' network scanning tool, which is commonly used for internal network discovery and vulnerability scanning. The rule monitors for the presence of the fscan binary or evidence of its output files, specifically 'result.txt', often in combination with scanning parameters like port strings or target service references.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
000
Detects execution and file artifacts associated with the 'fscan' network scanning tool, which is commonly used for internal network discovery and vulnerability scanning. The rule monitors for the presence of the fscan binary or evidence of its output files, specifically 'result.txt', often in combination with scanning parameters like port strings or target service references.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
000
Detects the execution of Python scripts named 'exploit.py' or 'exp.py', which are common naming conventions associated with proof-of-concept or exploit code.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
000
This rule detects potential exploitation activities targeting Atlassian Confluence by monitoring for unauthorized access to administrative configuration actions (e.g., setup/setupadministrator.action) and the subsequent addition of accounts to the 'confluence-administrators' group. It correlates process execution, network request patterns, and local user account modifications to identify successful or attempted privilege escalation and configuration manipulation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects an authentication event followed by a computer account change event (Event ID 4742) targeting a domain controller computer account. This pattern may indicate unauthorized modifications to domain controller machine accounts, which is often associated with persistence or privilege escalation attempts.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
30 days ago
007
Detects network communication originating from the 1C:Enterprise server process (rphost.exe) to a specific remote IP address and port associated with potential malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects outbound network connections made by 1C Enterprise processes (rmngr.exe or rphost.exe) to non-private/external IP addresses over specific ports (1541, 1570, 1571). These processes typically handle database server management and application host functions within the 1C platform, and direct external communication from them may indicate unauthorized activity or C2 traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects the execution of Python scripts named 'exploit.py' or 'exp.py', which are common naming conventions associated with proof-of-concept or exploit code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Page 337 of 1871