Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
002
Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
002
Detects remote file access (via SMB, named pipes, or TCP) to the Active Directory Certificate Services (AD CS) 'CertLog' directory. This directory contains the CA database (.edb), which holds issued certificates and archived private keys. Access to these files from a non-CA host is a strong indicator of an attempt to exfiltrate the CA database for offline certificate and private key recovery.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
6030
Detects text/report artifacts (markdown, JSON, plain text) produced by an autonomous AI-driven vulnerability research pipeline that decompiles binaries, traces cross-references, hypothesizes memory-safety flaws, and generates/debugs proof-of-concept exploits
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
002
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
002
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden windows) initiated by mshta.exe, excluding instances where a .ps1 script file is involved. This pattern often indicates attempts to bypass execution policy or run obfuscated payloads in memory, which is a common behavior of malicious HTA files.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
207
This rule detects the creation of a scheduled task using 'schtasks.exe' where the task name matches commonly abused names such as 'WinUpdate.exe', 'SoftManager.exe', or 'LockAppHost.exe'. These names are frequently used by adversaries to masquerade as legitimate Windows processes to achieve persistence.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
107
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
30 days ago
004
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
30 days ago
004
This rule detects potential attempts to tamper with Microsoft Defender security settings by creating or managing scheduled tasks that modify Defender exclusion paths. It correlates process execution (specifically schtasks.exe or PowerShell commands used for setting exclusions) with Windows Registry events that modify the Microsoft Defender exclusion path registry keys, flagging suspicious activity within a 15-minute window.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
1 month ago
8121
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
1 month ago
005
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
206
This rule detects outbound network connections from internal devices to a list of known malicious IP addresses associated with adversary command and control infrastructure. The rule specifically monitors connections over common ports, potentially indicating established communication with malicious servers.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
23 days ago
000
Detects execution or file presence of known malicious files based on a pre-defined list of SHA256 hashes associated with known threat activity.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
000
Detects anomalous child process execution originating from PaperCut application processes (pc-app.exe) or associated Java processes. This is indicative of post-exploitation activity following an RCE vulnerability where the application server is leveraged to spawn command interpreters, discovery utilities, or ingress tools.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
1 month ago
21149
Detects GhostContainer .NET-based backdoor assembly components deployed on compromised Exchange servers, requiring multiple corroborating unique indicators (module/class names, C2 header, masquerading filenames) to reduce false positives on generic .NET assemblies
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
000
Detects GhostContainer .NET-based backdoor assembly components deployed on compromised Exchange servers, requiring multiple corroborating unique indicators (module/class names, C2 header, masquerading filenames) to reduce false positives on generic .NET assemblies
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
000
This rule detects potential web shell creation on a Microsoft Exchange server by monitoring for suspicious child processes spawned by the IIS web server process (w3wp.exe) that correlate with the creation or modification of web-accessible script files (.aspx, .ashx, .asp, .dll) within the Exchange virtual directories (ecp, owa, aspnet_client). This pattern is consistent with common post-exploitation activities used by attackers to gain persistent access via web shells.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
000
This rule detects potential web shell creation on a Microsoft Exchange server by monitoring for suspicious child processes spawned by the IIS web server process (w3wp.exe) that correlate with the creation or modification of web-accessible script files (.aspx, .ashx, .asp, .dll) within the Exchange virtual directories (ecp, owa, aspnet_client). This pattern is consistent with common post-exploitation activities used by attackers to gain persistent access via web shells.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
000
This rule detects potential web shell creation on a Microsoft Exchange server by monitoring for suspicious child processes spawned by the IIS web server process (w3wp.exe) that correlate with the creation or modification of web-accessible script files (.aspx, .ashx, .asp, .dll) within the Exchange virtual directories (ecp, owa, aspnet_client). This pattern is consistent with common post-exploitation activities used by attackers to gain persistent access via web shells.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
000
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
000
Page 362 of 1870