Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects the creation, modification, or renaming of 'ntdll.dll' within a specific directory path matching the pattern 'ShieldCrash_{GUID}'. This pattern is indicative of potential malicious activity, such as the use of NTFS Alternate Data Streams (ADS) for persistence or execution evasion. The rule explicitly excludes known legitimate system processes that may handle DLL files to minimize noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
003
This rule detects the creation, modification, or renaming of 'ntdll.dll' within a specific directory path matching the pattern 'ShieldCrash_{GUID}'. This pattern is indicative of potential malicious activity, such as the use of NTFS Alternate Data Streams (ADS) for persistence or execution evasion. The rule explicitly excludes known legitimate system processes that may handle DLL files to minimize noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
003
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
103
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
203
Detects the eicar_com.zip test archive used by the ShieldCrash PoC (CVE-2026-69414) to trigger Windows Defender's vulnerable scan/read path, only when observed alongside ShieldCrash binary or staging path/context indicators to reduce false positives from routine EICAR AV testing
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
003
Detects the Warden.dll companion DLL shipped as part of the ShieldCrash (CVE-2026-69414) exploit chain, tightened to require an unsigned/unknown publisher or a suspicious install path alongside the generic filename
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
103
Detects rapid deletion and creation cycles of the WD_SCAN object manager link, a behavioral pattern associated with a Time-of-Check-to-Time-of-Use (TOCTOU) exploit chain targeting Windows Defender (referenced as CVE-2026-69414). The rule monitors for at least three cycle events occurring within a 5-second window, specifically involving the 'WD_SCAN' object identifier.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
203
Detects high-frequency file creation, modification, or renaming activity involving files with the specific '.df_win' extension, likely indicative of mass encryption activity or automated ransomware behavior. The rule excludes known backup and security software processes to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
003
Detects DragonForce ransomware note (readme.txt) referencing known DragonForce Tor negotiation/blog onion addresses
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
003
This rule detects potentially malicious activity where multiple critical processes (such as database engines or email clients) are terminated in a short time frame, correlated with a high volume of file creation or modification events on the same device. This behavior is indicative of destructive activity, such as ransomware encrypting data stores or disabling defensive software.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
203
The following analytic detects renaming of Windows built-in accounts via Event ID 4781.
It identifies renames targeting accounts with well-known reserved RIDs (500-504): Administrator, Guest, krbtgt, DefaultAccount, and WDAGUtilityAccount, by matching the TargetSid field against the S-1-5-21-*-50[0-4] pattern.
Attackers commonly rename the built-in Administrator account to evade detections that alert on the literal account name, while retaining the full privileges of the RID-500 account.
Renaming Guest, krbtgt, or other reserved accounts is highly unusual in any legitimate environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
206
Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.
avatar
Ankit Mehta@Secvyn
Defender - KQL
30 days ago
103
Detects outbound network traffic containing cleartext Windows command shell banners, which is highly indicative of a reverse shell connection where a remote attacker has established interactive command-line access to a compromised host.
avatar
Ali AlEnezi@site
avatar
Detections.ai Community
24 days ago
000
This rule detects browser activity where a page rendered via a data blob loads a sandboxed iframe containing cross-origin content originating from cdn.bloom.io. This pattern is consistent with known phishing delivery mechanisms often used in DocuSign or Teams-themed phishing campaigns to facilitate credential theft or secondary payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
702
Detects the execution of known development, scripting, and administrative tools (e.g., Python, Node.js, GCC, Docker) from non-standard or unauthorized file paths. The rule leverages allowlists for process names, publishers, and trusted installation directories to identify potentially unauthorized usage of powerful tooling often abused by attackers for post-exploitation activities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
Detects the execution of known development, scripting, and administrative tools (e.g., Python, Node.js, GCC, Docker) from non-standard or unauthorized file paths. The rule leverages allowlists for process names, publishers, and trusted installation directories to identify potentially unauthorized usage of powerful tooling often abused by attackers for post-exploitation activities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
This rule monitors network traffic and internal logs for connections to known malicious IP addresses or domain names associated with 'ClickFix' social engineering campaigns (often impersonating services like HBO Max). The logic explicitly filters out known threat intelligence scanners and security researcher probes. It performs correlation by requiring domain/message matches for generic IP-based alerts to reduce noise, and aggregates events per host over 15-minute windows to produce consolidated alerts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
Detects network communication with domains and IP addresses known to be associated with 'ClickFix' social engineering campaigns (specifically those masquerading as legitimate HBO Max or macOS related updates). The rule applies a strict correlation between observed malicious IP traffic and specific DNS requests to reduce noise from IP address reuse or threat intelligence feed probes, while also excluding known security-related processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
Detects unauthorized processes (e.g., cmd.exe, powershell.exe, node.exe) accessing sensitive web browser files like 'Login Data' or 'Cookies' in common browser directories. This behavior is indicative of credential theft or data exfiltration attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
105
Detects unauthorized attempts to exercise Active Directory replication rights (DS-Replication-Get-Changes). This occurs when non-machine accounts access specific control access rights (GUIDs 1131f6aa, 1131f6ad, or 89e95b76) on a domain controller, a common indicator of a DCSync attack used to extract password hashes from Active Directory.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
4016
This rule detects potentially malicious activity involving the modification of Excel macro security settings (specifically VBAWarnings or AccessVBOM) or the creation of autorun.inf files on removable drives. It identifies these behaviors when they coincide with the execution of Synaptics.exe within a 30-minute window, suggesting a potential correlation between local administrative tasks and malicious document-based payloads or portable drive staging.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
27 days ago
001
Page 374 of 1870