Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
003
Detects remote administration activity via Windows Management Instrumentation (WMI) originating from a host that has no recorded history of performing such actions within the previous 30 days. This includes the use of wmic.exe for remote nodes, Invoke-WmiMethod, or WmiPrvSe.exe spawning common command-line interpreters or utilities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
003
Detects modifications to Windows Registry keys intended to disable System Restore, User Account Control (UAC), or automatic Windows Updates, which is indicative of an attacker attempting to impair system defenses or inhibit recovery capabilities.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
001
Detects the creation of ransom notes by the OpnKey ransomware family, which specifically uses the filename #Restore-My-Files.txt. This file is a characteristic indicator of the ransomware's post-encryption activity.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
001
Detects forged Citibank payment confirmation/account statement PDFs used in Phantom Deal BPC fraud to falsely demonstrate wire transfer progress; requires combination of bank branding with fraud-specific SWIFT/routing/CTA artifacts
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
003
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
002
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
002
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
002
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
002
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
002
Detects instances where node, npm, or bun package installation processes modify the Claude AI settings.json file. This could indicate potential supply chain compromise or unauthorized configuration changes to the Claude application environment via malicious packages or scripts.
avatar
Hrushikesh Badgujar@H3AD
avatar
Detections.ai Community
27 days ago
102
Detects instances where the GlobalProtect VPN client executable spawns a Windows command shell (cmd.exe). This behavior is highly suspicious as a legitimate VPN client typically does not launch interactive shells, and this pattern has been associated with the execution of malicious payloads such as fake MSI installers.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
206
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
003
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
606
Detects the creation of files named 'strEncodedData.txt' on the local file system. This naming convention is associated with the DarkTortilla RAT, which uses this specific file to stage encoded data prior to exfiltration or further processing.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
1 month ago
106
Detects processes using Python shutil.copyfile to harvest sensitive browser data files from Chromium-based profiles.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
9013
Detects suspicious Kerberos ticket requests via command line using System.IdentityModel.Tokens.KerberosRequestorSecurityToken class.
Threat actors may use command line interfaces to request Kerberos tickets for service accounts in order to
perform offline password cracking attacks commonly known as Kerberoasting or other Kerberos ticket abuse
techniques like silver ticket attacks.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
25 days ago
001
Detects the execution of known offensive security tools often used for lateral movement, credential dumping, and remote code execution, such as Impacket modules and the 'Invoke-TheHash' PowerShell suite, via common command-line interpreters.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
28 days ago
203
This rule monitors for process creation or file interaction events associated with a specific SHA256 file hash identified as malicious. It uses Microsoft Defender for Endpoint (MDE) logs to correlate both process execution and file activity related to this indicator of compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
003
This rule detects network connections and HTTP requests to known malicious URLs, including file downloads associated with C2 infrastructure and malware distribution campaigns. It monitors both direct device network events and HTTP requests logged through security product events to identify potential secondary-stage payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
304
This rule monitors for outbound network connections to domains and IP addresses associated with known phishing, loader, and C2 infrastructure, including specific ClickFix patterns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
7018
Page 361 of 1870