Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the creation of Object Manager symbolic links that redirect the Windows Defender 'WD_SCAN' object to a loopback UNC share path. This behavior is indicative of a symlink exploitation technique (ShieldCrash/CVE-2026-69414) used to manipulate Windows Defender or associated scan operations by redirecting them to an adversary-controlled or loopback-hosted target.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
307
Detects instances where a non-SYSTEM process attempts to open a handle to winlogon.exe. Since winlogon.exe typically runs as SYSTEM and manages user sessions, unauthorized access to its process handle is often a precursor to credential dumping or token manipulation attacks aimed at escalating privileges to SYSTEM.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
609
Detects unexpected crashes or restarts of the Windows Defender service (MsMpEng.exe) occurring in temporal proximity to activities associated with the ShieldCrash PoC or tampering within the Windows Defender object manager namespace. This rule aims to identify potential exploitation attempts targeting Windows Defender, specifically correlating security service instability with known malicious indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
507
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
3709
Detects the installation or execution of known remote access tools (RMM) from suspicious parent processes (browsers, archives) or from user-writable directories (Temp, Downloads). This behavior is characteristic of initial access and staging activities performed by ransomware operators or Initial Access Brokers (IABs). The rule excludes known IT-managed deployment paths and signed binaries used by the organization.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
309
This rule detects network communication, email interaction, or identity logon events related to known spoofed IC3 (Internet Crime Complaint Center) domains used in business email compromise (BEC) campaigns. The detection covers multiple telemetry sources including email URL information, device network events, and identity logon logs to identify attempts to interact with fraudulent portals.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
27 days ago
003
Detects the registration of browser service workers from suspicious sources. Service workers can be used to maintain persistence, intercept network requests, or perform browser-based man-in-the-middle attacks. This rule specifically alerts on service workers initialized with 'blob:' URIs or those originating from the suspicious 'cdn.bloom.io' domain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
105
This rule detects a suspicious sequence of activities indicative of potential lateral movement and credential access. It identifies the execution of PsExec (PSEXESVC.exe) in conjunction with volume shadow copy manipulation (vssadmin, wmic, or diskshadow to create or delete shadow copies) within a 30-minute window. It further correlates this activity with potential lateral movement commands (e.g., net.exe, query.exe, nslookup.exe) to assess the severity of the incident.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
24 days ago
001
This rule detects a suspicious sequence of activities indicative of potential lateral movement and credential access. It identifies the execution of PsExec (PSEXESVC.exe) in conjunction with volume shadow copy manipulation (vssadmin, wmic, or diskshadow to create or delete shadow copies) within a 30-minute window. It further correlates this activity with potential lateral movement commands (e.g., net.exe, query.exe, nslookup.exe) to assess the severity of the incident.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
001
Detects execution of potentially suspicious processes ('Launcher.exe' or 'GapiUpdate.exe') originating from ClickOnce-related processes ('dfsvc.exe' or 'rundll32.exe' with 'dfshim.dll'). ClickOnce is often abused to proxy execution of malicious code, allowing adversaries to execute applications from user-writable directories without administrative privileges.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
Detects NeedleStealer Rust-based stealer binaries via Go module path strings, C2 domain, build tag, and embedded browser wallet extension identifiers
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
Detects NeedleStealer Rust-based stealer binaries via Go module path strings, C2 domain, build tag, and embedded browser wallet extension identifiers
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
101
Detects NeedleStealer Rust-based stealer binaries via Go module path strings, C2 domain, build tag, and embedded browser wallet extension identifiers
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
Detects NeedleStealer Rust-based stealer binaries via Go module path strings, C2 domain, build tag, and embedded browser wallet extension identifiers
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects access to sensitive credential stores (KeePass databases, Firefox logins, SSH keys, VPN configuration files) by suspicious processes, specifically those associated with potential credential harvesting tools or unauthorized update binaries.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
Detects access to sensitive credential stores (KeePass databases, Firefox logins, SSH keys, VPN configuration files) by suspicious processes, specifically those associated with potential credential harvesting tools or unauthorized update binaries.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
This rule monitors network, DNS, and email activity to identify communication or references to a set of known malicious domains associated with threat activity. It consolidates logs from device network events, DNS queries, and email telemetry (URLs and sender domains) to detect potential compromise or phishing attempts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
24 days ago
101
Detects access to sensitive credential stores (KeePass databases, Firefox logins, SSH keys, VPN configuration files) by suspicious processes, specifically those associated with potential credential harvesting tools or unauthorized update binaries.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
This rule detects potential malicious activity by monitoring for specific file hashes, specific suspicious filenames, and suspicious command-line patterns (e.g., 'antivm') initiated by known update or launcher processes. This is likely an indicator of malware behavior involving anti-sandbox or evasion techniques.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
101
This rule detects potential malicious activity by monitoring for specific file hashes, specific suspicious filenames, and suspicious command-line patterns (e.g., 'antivm') initiated by known update or launcher processes. This is likely an indicator of malware behavior involving anti-sandbox or evasion techniques.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Page 340 of 1870