Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects suspicious file operations (creation, modification, or renaming) initiated by MsMpEng.exe (Microsoft Defender Antivirus) involving specific indicators related to ELAM (Early Launch Anti-Malware) or 'ShieldCrash' components. These indicators often suggest tampering attempts or the presence of tools designed to interfere with Defender's security operations by targeting its configuration, staging, or protected storage locations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
404
This rule detects suspicious file operations (creation, modification, or renaming) initiated by MsMpEng.exe (Microsoft Defender Antivirus) involving specific indicators related to ELAM (Early Launch Anti-Malware) or 'ShieldCrash' components. These indicators often suggest tampering attempts or the presence of tools designed to interfere with Defender's security operations by targeting its configuration, staging, or protected storage locations.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
104
Detects the Warden.dll companion DLL shipped as part of the ShieldCrash (CVE-2026-69414) exploit chain, tightened to require an unsigned/unknown publisher or a suspicious install path alongside the generic filename
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
004
Detects unexpected crashes or restarts of the Windows Defender service (MsMpEng.exe) occurring in temporal proximity to activities associated with the ShieldCrash PoC or tampering within the Windows Defender object manager namespace. This rule aims to identify potential exploitation attempts targeting Windows Defender, specifically correlating security service instability with known malicious indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
004
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
30 days ago
304
This rule detects potentially malicious activity associated with removable media (USB drives) by identifying two distinct patterns: first, the creation of an 'autorun.inf' file on a removable drive followed by the execution of a script or executable from that same drive shortly after. Second, it identifies executables appearing on removable media that are launched across multiple distinct hosts within a one-hour window, which may indicate worm-like spreading or mass-malware distribution via portable storage.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
005
Detects instances where an Azure AD Connect or MSOL synchronization account performs directory replication actions (DS-Replication-Get-Changes) from a host or at a time inconsistent with its 14-day established baseline. The rule further correlates these anomalies with Azure Audit logs or AzureActivity entries associated with the identity to identify potential cloud-originated abuse or credential compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
002
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
305
Detects Kerberos AS-REQ events (Event ID 4768) where accounts with Kerberos pre-authentication disabled successfully request an AS-REP ticket. Attackers exploit these accounts by requesting encrypted AS-REP blobs to perform offline password cracking. The rule flags potential enumeration when multiple unique accounts are targeted from the same source within a short timeframe.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
48022
Detects the loading of reflective (memory-only) DLLs within the chrome.exe process address space. This activity is indicative of memory-based exploit chains, such as those that corrupt WebAssembly module metadata to facilitate arbitrary code execution following a sandbox escape.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
003
Detects token duplication/impersonation targeting winlogon.exe to obtain SYSTEM privileges (SeDebugPrivilege abuse, DuplicateToken, SetTokenInformation to Untrusted integrity)
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
105
Detects known malicious file hashes for GRAYRABBIT delivery chain components: trojanized 7zp.dll loader, encrypted PE loader shellcode, and GRAYRABBIT backdoor core.dll, gated on PE structural validity and filesize
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
002
This rule detects the presence or execution of a file named 'GlobalProtect.exe' within the Palo Alto GlobalProtect directory. It focuses on identifying potentially masqueraded or unauthorized binaries by monitoring file events and associated process execution. This pattern is commonly used by attackers to disguise malicious files as legitimate security software to evade detection.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detection & Hunting Community
1 month ago
305
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
005
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
005
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
105
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
003
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
101
Detects potential Qilin ransomware binaries following Cisco FMC-based intrusion by UAT-11988. Source intel provides only name-level attribution (no sample hash/byte IOC for the payload), so this is tightened to a valid PE, a plausible ransomware-payload size band, and >=2 occurrences of the family string -- a bare single 'Qilin' substring in an arbitrary PE (e.g. an unrelated app, build path, or AV/report string) is not sufficient to alert on alone.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
003
Detects suspicious activities originating from CrowdStrike Falcon remediation processes (e.g., CSFalconService.exe, CSFalconContainer.exe). The rule identifies two distinct patterns: either a file operation (delete, modify, rename, quarantine, or restore) followed within 2 minutes by the loading of an unsigned or non-standard DLL, or the spawning of an elevated SYSTEM process from a non-SYSTEM parent process. This behavior is indicative of potential LPE (Local Privilege Escalation) abuse via the Falcon remediation engine, often referred to as FalconFlank-style exploitation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
7019
Detects a sequence of events where a user visits a Cloudflare Pages URL (*.pages.dev) and shortly after, a suspicious command (mshta, powershell, or curl) is executed. This pattern is consistent with the UNC5142 threat actor's TTP of using social engineering lures hosted on Cloudflare Pages to trick users into running malicious commands.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
306
Page 364 of 1870