Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
005
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
005
Detects forged NDA documents used in Phantom Deal fake acquisition fraud, requiring corroborating secrecy-clause language and M&A-fraud-specific wire-transfer/payment phrasing alongside impersonated advisory brands
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
004
Detects remote registry operations performed through the Winreg RPC interface. This behavior is commonly associated with adversary tools like secretsdump used to extract sensitive Windows registry hives such as SAM, SECURITY, and SYSTEM. Monitoring remote registry access is crucial for identifying unauthorized data collection and credential access attempts.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
28 days ago
304
Detects the installation or execution of common remote monitoring and management (RMM) tools, including AnyDesk, TeamViewer, ScreenConnect, and Quick Assist. These tools are frequently abused by adversaries for persistence and command-and-control post-compromise.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
30 days ago
606
Detects network connection attempts to specific external domains associated with suspicious JavaScript payloads. The rule filters for specific file paths (e.g., mpackage.js, bsc-loader.js) linked to known malicious or suspicious URL patterns on cdn.claritydelivr.com, rcrsinnovations.com, konverto.in, and cdn.api-middle-connect.com, which may indicate C2 beaconing or malware infection.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
5010
Detects post-exploitation persistence artifacts on Windows endpoints managed by N-able N-central consistent with abuse of CVE-2026-18577, including a new Windows service named Cloudflared, registry Services key creation for Cloudflared, a file named svchost.exe written under a user's Documents folder, or process execution of cloudflared.exe or a Documents-located svchost.exe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
1013
Detects unauthorized processes accessing sensitive web browser files (login data, cookies, local state) from suspicious or non-standard paths. This is a common behavioral pattern for infostealers attempting to exfiltrate user credentials and browser session tokens.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
306
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
207
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
306
Detects the ShieldCrash CVE-2026-69414 exploit PoC binary/PDB via multiple corroborating distinguishing strings and file size
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
206
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
306
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
206
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
006
Detects presence of multiple ShieldCrash CVE-2026-69414 PoC Visual Studio project/solution build artifacts indicating exploit tooling staging
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
106
Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
506
Detects Run key persistence pointing to the known VBScript staging directory (C:\Users\Public\Libraries\Default\Lib\Lib1) used by the worm-like ScreenConnect campaign (Aug 2026), matching known script filenames (WindowsServiceHost.vbs, 1.vbs-4.vbs) invoked via wscript.exe/cscript.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
206
This rule detects potential COM hijacking of the CLSID InprocServer32 registry keys or unauthorized loading/creation of the 'EhStoreShell.dll' file. These behaviors are common indicators of persistence mechanisms or DLL side-loading where attackers redirect legitimate system calls to malicious code.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
004
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
408
This rule detects modifications to the security descriptors (ACLs) of sensitive Active Directory objects, specifically targeting additions of powerful rights like GenericAll, GenericWrite, WriteDacl, or ForceChangePassword. Monitoring these changes on privileged objects such as Domain Admins, Enterprise Admins, and Domain Controllers is critical for detecting potential privilege escalation or persistence efforts.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
28 days ago
103
Page 347 of 1870