Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the creation, modification, or renaming of PHP files within the 'wp-content/uploads' directory of a WordPress installation. This pattern is commonly indicative of an attacker uploading a web shell to maintain persistence or execute arbitrary code on a compromised web server.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
106
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
105
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
000
Detects anomalous child process execution (e.g., cmd.exe, powershell.exe, whoami) by PaperCut application processes (java.exe, pc-app.exe, PCClient.exe), which is indicative of post-exploitation activity following an authentication bypass and remote code execution chain against PaperCut NG/MF.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
206
Detects nm_host.exe (PEEP native messaging host binary) spawned by Chrome/Edge, tightened to require either the known PEEP extension ID in the native-messaging invocation command line or the distinctive com.peep.lab host path.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
105
Detects a DLL file being created directly under C:\Windows\System32 by a process running at less than System integrity (not SYSTEM/TrustedInstaller). Legitimate System32 DLL writes are performed by installers or the OS itself running with SYSTEM privileges; a standard-user or low/medium-integrity process writing a new DLL into this protected path is consistent with the HardBreacher/SolidSnake local privilege-escalation exploit chain. Scoped on protected-directory + non-privileged-writer, not on filename, to generalize to renamed variants.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
1 month ago
17041
Detects unauthenticated HTTP POST requests to the PaperCut web management interface that attempt to modify server configuration settings. This behavior is consistent with exploitation attempts targeting vulnerabilities like CVE-2026-81578, which may allow for unauthorized pre-authentication remote code execution.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
1 month ago
19343
The following analytic detects the creation or modification of adsource.dll or other staging files with the name adsource_*.dll within the SCCM SMS Provider bin directory, consistent with exploitation of CVE-2026-47301.
This abuses a DLL side-loading vulnerability in the Microsoft Configuration Manager SMS Provider component.
An attacker can plant a malicious adsource.dll in the SCCMProvider bin\X64 path, causing the SMS Provider service to load the attacker-controlled library in a privileged context.
The presence of renamed dlls alongside adsource.dll is a strong indicator of the classic DLL hijacking pattern where the legitimate library has been renamed so the malicious replacement can proxy calls to it.
If confirmed malicious, this activity represents a privilege escalation vector that can result in SYSTEM-level code execution on any host running the SCCM SMS Provider role.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
207
Detects node.js or bun runtime processes accessing known sensitive cloud, CI, and package manager credential files on disk. This behavior is indicative of malicious npm supply chain attacks (e.g., Mini Shai-Hulud) attempting to exfiltrate secrets stored in standard configuration paths.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
1 month ago
35242
This rule detects DNS queries or network connections originating from endpoints to a list of known malicious domains associated with various malware families (ClearFake, IClickFix, AMOS, Vidar, etc.). This helps identify potential C2 communication, malicious payload delivery, or infrastructure interaction.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
000
This rule detects DNS queries or network connections originating from endpoints to a list of known malicious domains associated with various malware families (ClearFake, IClickFix, AMOS, Vidar, etc.). This helps identify potential C2 communication, malicious payload delivery, or infrastructure interaction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
000
This rule monitors DeviceNetworkEvents for outbound network connections to a list of known malicious IP addresses associated with various C2 frameworks and malware families, as identified by threat intelligence feeds (e.g., ThreatFox). Identifying these connections helps detect potential C2 communication and ingress tool transfer.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
000
This rule detects network connections and HTTP requests to known malicious URLs, including file downloads associated with C2 infrastructure and malware distribution campaigns. It monitors both direct device network events and HTTP requests logged through security product events to identify potential secondary-stage payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
29 days ago
003
This rule detects the presence of files or process execution events matching a known set of SHA256 hashes associated with the BlueMoon malware family. The detection covers both file system events and process creation events.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
203
This rule detects DNS queries and network connections to a curated list of domains identified as malicious. It correlates events from DNS logs and device network logs to identify potential command-and-control (C2) or malicious infrastructure interaction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
203
This rule detects potential ransomware activity by correlating risky user identity events (such as impossible travel or malicious IP access) with subsequent endpoint behavior typical of ransomware, specifically the deletion of shadow copies or system backups, or mass file modification activity occurring within a short window.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
003
This rule detects potential ransomware activity by correlating risky user identity events (such as impossible travel or malicious IP access) with subsequent endpoint behavior typical of ransomware, specifically the deletion of shadow copies or system backups, or mass file modification activity occurring within a short window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
203
Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
109
This rule detects potential web skimmer activity where a user's browser performs a network connection to known payload delivery hosts (e.g., paste.sh or Google Sheets API) followed by a clipboard modification event on the same device within a one-hour window. This behavior is consistent with malicious scripts attempting to replace copied cryptocurrency wallet addresses with an attacker-controlled address.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
003
Detects the creation of WMI event filters and consumers associated with CommandLineEventConsumer or ActiveScriptEventConsumer, excluding known legitimate system processes. This behavior is a common technique for establishing persistence and executing arbitrary code via WMI event subscriptions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
102
Detects the creation of WMI event filters and consumers associated with CommandLineEventConsumer or ActiveScriptEventConsumer, excluding known legitimate system processes. This behavior is a common technique for establishing persistence and executing arbitrary code via WMI event subscriptions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
002
Page 365 of 1870