Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects OAuth2 JWT bearer-grant token requests to Google's OAuth endpoint using the attacker-controlled service-account identity and Sheets API scope observed in the fake GlobalProtect campaign
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
408
Detects network requests to Google Sheets API containing specific markers (-tk- or val-) in the request body, indicative of potential command and control (C2) communication patterns often associated with malware payloads using Google Sheets for data exfiltration or command retrieval.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
408
Detects Mimikatz binary or in-memory module used for credential harvesting following PaperCut RCE exploitation
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
002
Detects Mimikatz binary or in-memory module used for credential harvesting following PaperCut RCE exploitation
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
002
Detects the execution of BloodHound/SharpHound reconnaissance tools and the presence of their generated output files (ZIP or JSON format) on a host. This rule monitors both the process creation events associated with the tool's execution and file creation events indicative of data staging or collection output.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
102
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to execute processes, particularly when a remote node target is specified or when using common WMI process creation arguments. This pattern is commonly used by adversaries for lateral movement and remote code execution while attempting to blend into administrative activity. Legitimate management tools have been excluded from the scope to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
604
Detects anomalous system reconnaissance activity performed using WMIC or PowerShell Get-WmiObject commands. The rule tracks distinct command-line executions per device and flags hosts where three or more unique reconnaissance commands are executed within a short timeframe, which is indicative of an adversary enumerating system configuration, hotfixes, or hardware details.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
104
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
404
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
404
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
101
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
001
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
101
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
001
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
005
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
005
Page 346 of 1870