Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
000
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
000
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
000
This rule detects HTTP requests directed at Microsoft Exchange Outlook Web Access (OWA) that contain suspicious 'fakePath' and 'fakePageName' parameters in the URI. These parameters are indicators of the 'GhostContainer' malware attempting to establish a socket forwarding proxy through the web server to facilitate command and control communications.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
000
This rule detects HTTP requests directed at Microsoft Exchange Outlook Web Access (OWA) that contain suspicious 'fakePath' and 'fakePageName' parameters in the URI. These parameters are indicators of the 'GhostContainer' malware attempting to establish a socket forwarding proxy through the web server to facilitate command and control communications.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
000
Detects the GhostContainer .NET-based backdoor assembly deployed on compromised Microsoft Exchange servers, requiring multiple corroborating unique indicators (C2 header, proxy class name, virtual path parameters) alongside .NET/PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
000
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
000
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
000
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
000
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
000
Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
004
Detects the use of command-line tools like curl, wget, PowerShell, or Python to perform DNS over HTTPS (DoH) queries, identified by specific command-line arguments and connections to known public DoH resolvers. This behavior can be indicative of attempts to bypass local DNS monitoring or security controls.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
19039
Detects the presence of the Docro Hijacker browser hijacker component (Adblock.dll) designed to tamper with Chrome's 'Secure Preferences' file. It specifically looks for indicators of HMAC-SHA256 integrity check bypass mechanisms used to force-install malicious browser extensions.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
30 days ago
004
This rule detects suspicious PowerShell execution that attempts to download files from the internet using the Invoke-WebRequest cmdlet. It specifically looks for PowerShell processes launched with hidden and execution policy bypass flags, coupled with specific hardcoded malicious URL patterns associated with a known campaign (NotaFiscal/nfe_valid_access_key_2026_secure).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
004
This rule identifies devices within the environment that are susceptible to CVE-2026-81963. It correlates vulnerability data with knowledge base information to flag the software, vendor, version, severity level, and the availability of public exploits for this specific vulnerability.
avatar
Mikio Nakamaru@mikionakamaru
avatar
Detections.ai Community
30 days ago
004
Detects a specific pattern of PowerShell execution involving the download of files from a remote endpoint using parameters associated with Brazilian tax documents (NotaFiscal) to the Desktop directory, followed by immediate execution. The rule looks for a combination of hidden window style, Invoke-WebRequest, specific URL parameters (dl.php, NFe identifiers), and subsequent Start-Process calls, which is indicative of malware dropper activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
004
This rule detects the creation, modification, or renaming of 'ntdll.dll' within a specific directory path matching the pattern 'ShieldCrash_{GUID}'. This pattern is indicative of potential malicious activity, such as the use of NTFS Alternate Data Streams (ADS) for persistence or execution evasion. The rule explicitly excludes known legitimate system processes that may handle DLL files to minimize noise.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
104
Detects suspicious file activity within directories named 'ShieldCrash' followed by a cloud provider registration or placeholder creation event within a 5-minute window. This behavior is indicative of unauthorized software or an adversary attempting to stage data for exfiltration or create persistent storage aliases outside of legitimate cloud client applications.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
404
Detects the eicar_com.zip test archive used by the ShieldCrash PoC (CVE-2026-69414) to trigger Windows Defender's vulnerable scan/read path, only when observed alongside ShieldCrash binary or staging path/context indicators to reduce false positives from routine EICAR AV testing
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
004
Detects the eicar_com.zip test archive used by the ShieldCrash PoC (CVE-2026-69414) to trigger Windows Defender's vulnerable scan/read path, only when observed alongside ShieldCrash binary or staging path/context indicators to reduce false positives from routine EICAR AV testing
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
104
This rule detects suspicious file operations (creation, modification, or renaming) initiated by MsMpEng.exe (Microsoft Defender Antivirus) involving specific indicators related to ELAM (Early Launch Anti-Malware) or 'ShieldCrash' components. These indicators often suggest tampering attempts or the presence of tools designed to interfere with Defender's security operations by targeting its configuration, staging, or protected storage locations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
404
Page 363 of 1870