Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
002
Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
102
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
002
Detects remote administration activity via Windows Management Instrumentation (WMI) originating from a host that has no recorded history of performing such actions within the previous 30 days. This includes the use of wmic.exe for remote nodes, Invoke-WmiMethod, or WmiPrvSe.exe spawning common command-line interpreters or utilities.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
102
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
002
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
102
Detects high-frequency, automated web scraping behavior targeting product catalog pages, indicative of content harvesting for site replication. The rule monitors IIS logs for non-browser user agents (e.g., Python, curl, Scrapy) performing rapid, multi-page requests within a short duration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
002
Detects network connections to known command and control (C2) infrastructure, including hardcoded malicious domains, specific C2 IP addresses, and suspicious GitHub access patterns by processes other than standard web browsers, which may indicate malicious ingress tool transfer or C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
103
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
607
Detects outbound network connections initiated by the VLC media player (vlc.exe) to public IP addresses using the RTSP protocol (port 554) or referencing common media file extensions (e.g., .m3u, .xspf) in the command line. This behavior is often associated with remote stream retrieval or, in adversarial contexts, the potential use of media players to exfiltrate data or retrieve malicious remote payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
26 days ago
001
Detects the deletion of volume shadow copies using common Windows administrative utilities including vssadmin.exe, wmic.exe, diskshadow.exe, or through PowerShell WMI/CIM cmdlets. This behavior is frequently associated with ransomware and data destruction attacks aiming to prevent system recovery.
avatar
Ankit Mehta@Secvyn
Defender - KQL
24 days ago
000
Detects the deletion of volume shadow copies using common Windows administrative utilities including vssadmin.exe, wmic.exe, diskshadow.exe, or through PowerShell WMI/CIM cmdlets. This behavior is frequently associated with ransomware and data destruction attacks aiming to prevent system recovery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
000
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
avatar
Ankit Mehta@Secvyn
Defender - KQL
30 days ago
003
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
avatar
Ankit Mehta@Secvyn
Defender - KQL
30 days ago
103
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
30 days ago
103
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
30 days ago
303
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
Detects access to sensitive credential stores (KeePass databases, Firefox logins, SSH keys, VPN configuration files) by suspicious processes, specifically those associated with potential credential harvesting tools or unauthorized update binaries.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
000
Page 366 of 1870