Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the placement of potentially malicious executable or script files onto a network share followed by the execution of that specific file path from a different host within a short timeframe. This behavior is indicative of lateral movement using tainted shared content.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects potential remote service session hijacking by monitoring for RDP session ID reuse by a different user or unauthorized SSH session reattachment (e.g., tmux/screen hijacking). It correlates logon events with process execution to identify instances where an existing session is accessed by an account other than the original owner, while excluding legitimate service/support account activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
101
This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects high-frequency, automated web scraping behavior targeting product catalog pages, indicative of content harvesting for site replication. The rule monitors IIS logs for non-browser user agents (e.g., Python, curl, Scrapy) performing rapid, multi-page requests within a short duration.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the creation of WMI event filters and consumers associated with CommandLineEventConsumer or ActiveScriptEventConsumer, excluding known legitimate system processes. This behavior is a common technique for establishing persistence and executing arbitrary code via WMI event subscriptions.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to execute processes, particularly when a remote node target is specified or when using common WMI process creation arguments. This pattern is commonly used by adversaries for lateral movement and remote code execution while attempting to blend into administrative activity. Legitimate management tools have been excluded from the scope to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the use of PowerShell cmdlets such as Invoke-WmiMethod, Invoke-CimMethod, Get-CimInstance, or Get-WmiObject to interact with the Win32_Process class for process creation on local or remote systems. This behavior is frequently associated with administrative activity but is also commonly used by adversaries for remote command execution and lateral movement.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects anomalous system reconnaissance activity performed using WMIC or PowerShell Get-WmiObject commands. The rule tracks distinct command-line executions per device and flags hosts where three or more unique reconnaissance commands are executed within a short timeframe, which is indicative of an adversary enumerating system configuration, hotfixes, or hardware details.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
101
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects anomalous network traffic patterns characterized by rapid domain rotation, where multiple distinct domains resolve to a known set of IronToll C2 infrastructure IP addresses within a short timeframe (48 hours). Added an explicit 2-day lookback window — the original query had no time bound at all, so every scheduled run re-scanned the table's entire retention period and would keep re-surfacing the same historical match indefinitely instead of only genuinely recent activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects Ruby source files containing a hardcoded RubyGems API key (rubygems_ prefixed token) used for unauthorized gem publish/push actions, as seen in the yardxabc889 package from the GemStuffer campaign
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Page 373 of 1870