Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

This rule detects potential extraction or caching of Kerberos Ticket-Granting Tickets (TGT) by correlating Kerberos authentication events (4768/4769) with unauthorized access to the Local Security Authority Subsystem Service (lsass.exe). This pattern is often indicative of credential dumping tools like Mimikatz targeting Kerberos tickets on systems potentially used for delegation attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
004
This rule detects potential Kerberoasting reconnaissance activities by monitoring for the usage of 'setspn.exe' (Event ID 4688) or LDAP queries involving 'servicePrincipalName' (Event ID 1644). Adversaries use these methods to identify service accounts in the domain to target for ticket requests.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
004
Detects the execution of BloodHound related processes combined with a high volume of LDAP queries (Event ID 1644), which is indicative of Active Directory environment reconnaissance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
004
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
28 days ago
104
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
004
Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
004
This rule detects potential ransomware activity by correlating three distinct indicators: deletion of Volume Shadow Copies (using native Windows utilities), mass file modifications (>100 files in 15 minutes), and the creation or modification of files typically associated with ransom notes. The rule uses an inner join to ensure these events happen within a 30-minute window of each other on the same device.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
003
This rule detects potential ransomware activity by correlating three distinct indicators: deletion of Volume Shadow Copies (using native Windows utilities), mass file modifications (>100 files in 15 minutes), and the creation or modification of files typically associated with ransom notes. The rule uses an inner join to ensure these events happen within a 30-minute window of each other on the same device.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
003
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
003
Detects the execution of rundll32.exe with a command line pointing to a WebDAV share path (DavWWWRoot). This technique is commonly used to execute remote payloads by forcing the system to access a remote resource, often as part of a malicious DLL loading chain.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
107
Detects the GoCaracal lightweight implant performing process injection by identifying combinations of remote process memory allocation (VirtualAllocRemoteApiCall), memory writing (WriteProcessMemoryRemoteApiCall), and remote thread creation (CreateRemoteThreadApiCall) associated with specific suspicious filenames. It also monitors command-line activity for injection-related flags.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
This rule monitors for active reconnaissance or scanning behavior by detecting a single source IP interacting with a high number of distinct ports/hosts within a short time frame (NetworkScan) or accessing a high number of distinct URI paths/404 errors (WebContentScan).
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects potential web reconnaissance or scanning activity against Microsoft IIS servers. The rule identifies suspicious behavior by monitoring for high frequencies of distinct URI requests, excessive 404 Not Found status codes indicative of path brute-forcing, and the presence of known security scanning user-agents.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
203
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects instances where 'TieringEngineService.exe' or 'MsMpEng.exe' (Windows Defender) create, modify, or rename executable, library, or system files within the 'C:\Windows\System32\' directory. This behavior is highly irregular as these processes should not be authoring binaries in protected system folders, and may indicate process masquerading, unauthorized persistence, or defense evasion.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects suspicious DLL loads or file drops performed by security product processes (avp.exe, MsMpEng.exe) from directories outside of standard, trusted vendor paths. It specifically flags unsigned or invalidly signed DLLs, which is indicative of DLL sideloading techniques used to abuse security software workflows for potential privilege escalation.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
This rule detects the execution of a file named 'report.bin' and correlates it with subsequent network connections originating from the same process. This behavior is indicative of a potential C2 heartbeat or exfiltration activity involving a non-standard or obfuscated executable.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects the execution or presence of files, processes, or paths associated with the 'SnowKiller' malware or tool, as identified by keyword matching in process event logs.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
103
This rule detects the installation of browser extensions that occur during an idle user session (greater than 7 minutes). This behavior is consistent with automated, remote-driven synthetic input injection, often utilized by malware (e.g., NinjaMare) to install malicious extensions without user consent while the system is unattended.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects the creation of PHP files within the 'wp-content/uploads/elementor/forms/' directory of a WordPress installation. This behavior is highly suspicious as it often indicates an attempt by an attacker to deploy a web shell or other malicious script following successful exploitation of the Elementor plugin, which allows for arbitrary file uploads.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects Evil-WinRM / WinRM-fs usage or wsmprovhost.exe-spawned PowerShell tied specifically to bird-agent backdoor artifacts (cplsupport, wtass, config.toml) or encoded/download-cradle command patterns, rather than any WinRM session, reducing noise from routine remote administration.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Page 338 of 1871