Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
000
This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
000
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
000
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
000
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
000
Detects potential remote service session hijacking by monitoring for RDP session ID reuse by a different user or unauthorized SSH session reattachment (e.g., tmux/screen hijacking). It correlates logon events with process execution to identify instances where an existing session is accessed by an account other than the original owner, while excluding legitimate service/support account activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
107
Detects unauthorized file operations (creation, modification, or renaming) against the Windows hosts file located at C:\Windows\System32\drivers\etc\hosts. This is a common technique used by attackers to redirect network traffic, hijack domains, or disrupt communications to security services. The rule excludes common system processes known to perform legitimate maintenance on this file.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
000
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
000
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
003
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
003
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
000
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
000
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
000
This rule detects potentially malicious usage of the Windows RegSvcs.exe binary, often used as a proxy for executing code. It monitors for two specific patterns: RegSvcs.exe being executed from user-writable directories (e.g., C:\Users\, C:\ProgramData\), or RegSvcs.exe spawning suspicious child processes (e.g., PowerShell, cmd, WScript, mshta), which is indicative of a living-off-the-land (LotL) attack technique to bypass application control or execute payloads.
avatar
F S@Fsdr
avatar
Detections.ai Community
28 days ago
103
Page 352 of 1870