Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
Detects the creation or modification of Windows Registry run keys (Run or RunOnce) that attempt to point to executables within 'ProgramData\Synaptics' or named 'synaptics.exe'. This behavior is characteristic of adversaries attempting to establish persistence by masquerading as legitimate Synaptics driver software, while excluding legitimate installation directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
001
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
000
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
This rule detects potentially malicious activity involving the modification of Excel macro security settings (specifically VBAWarnings or AccessVBOM) or the creation of autorun.inf files on removable drives. It identifies these behaviors when they coincide with the execution of Synaptics.exe within a 30-minute window, suggesting a potential correlation between local administrative tasks and malicious document-based payloads or portable drive staging.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
001
Detects execution and file activity associated with the XRed backdoor, which masquerades as 'Synaptics.exe' by running from the non-standard 'C:\ProgramData\Synaptics\' directory instead of authorized system paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
001
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
000
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
000
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
000
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
Detects network requests to unpkg.com or npmmirror for 'index.html' files directly under a package path. This behavior deviates from standard package management usage (which typically fetches tarballs or specific JavaScript modules) and is often associated with adversaries using npm packages as hosting infrastructure for phishing landing pages.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
107
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
101
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Page 375 of 1870