Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the deletion of Volume Shadow Copies and disabling of Windows boot recovery options using native administrative utilities such as vssadmin, wmic, powershell, wbadmin, and bcdedit. This behavior is frequently associated with pre-encryption activities in ransomware attacks to prevent system restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects potential reflective DLL injection or process hollowing attempts by monitoring for high-privilege cross-process access (ProcessAccess EventID 10) or remote thread creation (CreateRemoteThread EventID 8). These methods are frequently used by attackers to execute malicious code within the memory space of a legitimate target process, thereby evading traditional signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the suspicious execution of common Windows system binaries (LOLBAS) often used for proxying malicious code execution or deobfuscating payloads. This includes regsvr32.exe for remote scriptlet execution, mshta.exe for remote HTA execution, rundll32.exe for JavaScript or DLL function execution, and certutil.exe for decoding or retrieving remote files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
201
Detects potential Pass-the-Hash (PtH) activity where a single user account performs NTLM Type 3 (network) authentications to three or more unique destination hosts within a 10-minute window, excluding service account activity (trailing $). This pattern is consistent with an adversary moving laterally across a network using harvested NTLM hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in-memory by monitoring command lines of common script-hosting processes (e.g., PowerShell, WScript, Rundll32) for strings indicative of AmsiScanBuffer patching, reflection, or manual configuration of AMSI initialization states.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects the use of the built-in Windows utility rundll32.exe to execute comsvcs.dll with the MiniDump command to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. This is a common technique used by attackers to harvest credentials from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the use of native Windows utilities (vssadmin, wbadmin, bcdedit, wmic) to delete shadow copies, backup catalogs, or modify boot configuration data to disable recovery. This behavior is commonly associated with ransomware and data destruction attacks intended to prevent system restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule detects unauthorized directory replication requests (DRSUAPI) using Active Directory Event ID 4662. It specifically monitors for access requests to sensitive directory replication object GUIDs (Get-Changes / Get-Changes-All) where the requesting user account is not a domain controller computer account. This behavior is a common indicator of DCSync credential dumping attacks performed by tools like Mimikatz or Impacket.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the 'ClickFix' technique where a user copies a malicious payload and pastes it into the Windows Run dialog (Win+R). The rule monitors for the creation of registry values under the RunMRU key followed closely by the execution of powershell.exe or cmd.exe initiated directly by explorer.exe, indicating an bypass of standard browser execution chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
002
This rule detects persistence establishment via Scheduled Task creation shortly (within 15 minutes) after a suspicious PowerShell process execution. The PowerShell execution matches the 'ClickFix' pattern, characterized by hidden/bypass window styles and the invocation of remote download or execution cmdlets (e.g., IEX, IRM).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
102
This rule detects potentially malicious in-memory module loading, such as Beacon Object File (BOF) execution, on hosts already identified as exhibiting suspicious behavior related to MLTBackdoor or sideloading activity. It monitors for memory allocation or protection changes (AllocateVirtualMemory, VirtualProtect, CreateRemoteThread) that result in executable memory (RWX or execute-only) without a corresponding file on disk, which is a common indicator of fileless code injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
002
This rule detects potential Browser-in-the-Browser (BitB) phishing attacks by identifying suspicious browser pop-up behavior (using window.open flags, hidden address/toolbars) on non-identity-provider domains, followed shortly by credential submission patterns on the same device. This pattern mimics legitimate OAuth or SSO windows to harvest user credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
102
Detects anomalous access to the SharePoint WebPartPages.asmx SOAP endpoint, specifically using the GetWebPartPageConnectionInfo method. This query identifies patterns consistent with the exploitation of CVE-2026-65660, where adversaries attempt to smuggle WebPart template markup (e.g., <%@ Register, XamlServices) after legitimate preview methods have been disabled.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
003
This rule detects potentially malicious POST requests to SharePoint endpoints (such as AddGallery.aspx) that include indicators of WebPartMarkup or ToolPane payloads. This activity attempts to bypass the SPUtility.EnsureAuthentication() check that is typically enforced on the ToolPane.aspx page, potentially allowing unauthorized code execution or configuration manipulation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
103
Detects the execution of binaries that masquerade as legitimate Adobe-signed applications by running from non-standard locations, while simultaneously performing DLL side-loading by loading a malicious 'msvcp140.dll' from the same directory as the executable.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
This rule monitors for known suspicious RPC interface and function calls indicative of post-exploitation activities. It specifically targets RPC patterns used for lateral movement (e.g., PsExec, wmiexec, dcomexec), authentication coercion (e.g., PetitPotam, PrinterBug), and credential theft (e.g., DCSync, SAMR enumeration) by filtering on specific interface UUIDs and operation numbers.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
18 days ago
2019
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
001
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
101
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
001
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
001
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
101
Page 36 of 1866