Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects post-exploitation persistence artifacts on Windows endpoints consistent with abuse of CVE-2026-18577.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
003
Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
003
This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
004
Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
004
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
205
This rule detects the creation of Windows services with specific, potentially suspicious names (wscl-13, msvcsrvc) configured to start automatically on system startup. The detection logic monitors command-line activity from sc.exe or services.exe to identify these specific service registrations.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
30 days ago
003
Detects the use of PowerShell to modify Microsoft Defender Antivirus configurations, specifically adding file exclusions or disabling protection features like Real-time or IOAV monitoring. These actions are common indicators of an adversary attempting to disable security controls to evade detection.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
30 days ago
003
Detects the modification or creation of scheduled tasks using OOBETaskScheduler or referencing Windows Servicing paths, combined with network connections to known malicious domains identified in threat intelligence.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
30 days ago
203
This KQL inventories activity associated with a specified root domain and its subdomains across DeviceNetworkEvents, EmailUrlInfo, CloudAppEvents.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
1 month ago
2112
This rule detects potential COM hijacking of the CLSID InprocServer32 registry keys or unauthorized loading/creation of the 'EhStoreShell.dll' file. These behaviors are common indicators of persistence mechanisms or DLL side-loading where attackers redirect legitimate system calls to malicious code.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
28 days ago
502
Detects the presence of known malicious Outlook VBA project files (VbaProject.OTM), modifications to Outlook macro-security registry keys to enable macro execution, and subsequent network activity initiated by Outlook on devices that have exhibited these suspicious behaviors.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
28 days ago
202
Detects the presence of known malicious Outlook VBA project files (VbaProject.OTM), modifications to Outlook macro-security registry keys to enable macro execution, and subsequent network activity initiated by Outlook on devices that have exhibited these suspicious behaviors.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
28 days ago
102
This rule detects potentially malicious behavior associated with Microsoft Office applications, such as Word, initiating suspicious WebDAV network connections, dropping executable or sensitive files, or spawning known LOLBAS processes (rundll32, explorer, regsvr32) from suspicious directories like Temp or WebDAV paths. It also includes a blocklist for known malicious file hashes associated with these patterns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
202
Detects the download of ZIP files with filenames matching known phishing patterns associated with NFe (Nota Fiscal Eletrônica) campaigns, correlated with access to specific malicious or suspicious download URLs within a 15-minute window.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
103
Detects the execution of known Windows update-related binaries (UpdateAssistant.exe or AppUpdateHelper.exe) from non-standard, suspicious locations within AppData directories. This behavior is indicative of masquerading, where an adversary attempts to blend in by using a legitimate process name from an unexpected path.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
203
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
003
Detects a specific pattern of PowerShell execution involving the download of files from a remote endpoint using parameters associated with Brazilian tax documents (NotaFiscal) to the Desktop directory, followed by immediate execution. The rule looks for a combination of hidden window style, Invoke-WebRequest, specific URL parameters (dl.php, NFe identifiers), and subsequent Start-Process calls, which is indicative of malware dropper activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
003
Detects the execution of Python scripts explicitly named 'socks5.py'. This is a common pattern used by adversaries to establish proxying capabilities for command and control or to tunnel traffic through a compromised host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
102
This rule detects attempts to disable, terminate, or misconfigure security software, including antivirus, EDR, and endpoint protection solutions, by monitoring the execution of system administration binaries (such as taskkill, net, sc, wmic, powershell) with command-line arguments indicating service or process stopping, deletion, or configuration changes related to security-specific product names.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
102
This rule detects potential tampering with the Huorong security product by monitoring for specific process names (HipsTray.exe, HipsMain.exe, HipsDaemon.exe, wsctrlsvc.exe, TrafficProt.exe) interacting with suspicious API calls or command lines indicative of token privilege manipulation, service blinding, or security product disabling/downgrade.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
304
Detects network requests to Google Sheets API containing specific markers (-tk- or val-) in the request body, indicative of potential command and control (C2) communication patterns often associated with malware payloads using Google Sheets for data exfiltration or command retrieval.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
104
Page 369 of 1870