Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects modifications to the 'metrics_interval' registry value within the 'Software\SynapseAgent' key. This activity suggests configuration changes to the SynapseAgent, which could indicate tampering with agent telemetry or polling frequency.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects execution of PowerShell.exe initiated by cplsupport.exe with hidden window styles and non-interactive, no-profile flags, which is often indicative of obfuscated command execution or malicious script activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects the modification or creation of the 'SealedConfig' value within the 'Software\synapse\Config' registry key, correlated with the deletion of a 'config.toml' file on the same device. This pattern may indicate an adversary tampering with Synapse software configuration or attempting to remove audit/configuration trails.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
103
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
KQL Query from file: postgresql-server-executes-code-via-malicious-logical-decoding-plugin.kql
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
103
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects modifications to the Windows Registry that disable Microsoft Defender Tamper Protection. Tamper Protection is a security feature that prevents malicious changes to security settings, including the disabling of antivirus and real-time monitoring.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
203
Detects attempts to tamper with Microsoft Windows Defender configuration, specifically by modifying exclusion paths via PowerShell cmdlets (Add-MpPreference, Set-MpPreference), direct registry modifications, or forced Group Policy updates. It also monitors for the disabling of Tamper Protection via registry and the creation of scheduled tasks designed to apply Defender exclusions.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects the execution of processes named 'ProManager.exe' or 'ProManagerServicedc894.exe', which may be indicative of unauthorized software or potentially malicious activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
203
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
103
This rule detects file access, creation, modification, or renaming operations involving sensitive files associated with cryptocurrency wallets (Bitcoin, Electrum, ElectrumSV), game account configurations (Battle.net, Steam, Minecraft), and browser-based cookies (Roblox). The rule filters out legitimate process interactions, identifying suspicious activity from unknown or unauthorized applications potentially attempting to exfiltrate credentials or session tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
203
Detects malicious network connections, file downloads, or process execution associated with the REVSTEALER malware campaign, which utilizes hijacked YouTube channels to distribute fake game-cheat videos that lure users into downloading 'resightloader.exe' from specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
103
Detects the use of PowerShell to add Microsoft Defender exclusions (paths or extensions) where the process was initiated by or involves LockAppHost.exe. This behavior is indicative of an attempt to bypass security protections by excluding malicious artifacts from scanning.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects anomalous registry enumeration or modification activities targeting software uninstallation registry keys (Run/Uninstall). By monitoring for multiple subkey accesses by processes not associated with standard software management tools (like MsiExec or explorer), this rule identifies potential reconnaissance or software discovery patterns indicative of malicious activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
103
Detects periodic screen capture activity performed by Node.js or Electron-based processes, correlated with subsequent outbound network connections to public IP addresses within a short timeframe. This behavior is indicative of the JSCeal malware's surveillance and exfiltration module, where local reconnaissance via screenshotting is followed by data transmission.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects Node.js or Electron processes executing from suspicious paths (e.g., Temp, Roaming) while interacting with web browser credential files or executing commands consistent with automated credential dumping tools.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects the execution of Terraform commands (init, apply, plan) that interact with the 'registry.coder.com' domain, or direct network connections to the associated infrastructure. This may indicate the use of unauthorized or compromised Infrastructure-as-Code (IaC) modules or malicious supply chain activity involving Terraform configurations.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
003
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
203
Detects anomalous authentication behavior where a user account utilizes the same authentication session (LogonId) or material to authenticate across multiple distinct destination hosts in a short timeframe. This rule monitors for both NTLM (Type 3) and Kerberos (TGS/TGT) events, which are indicative of lateral movement techniques such as Pass-the-Hash or Pass-the-Ticket.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
103
Page 339 of 1871