Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
Detects instances where node, npm, or bun package installation processes modify the Claude AI settings.json file. This could indicate potential supply chain compromise or unauthorized configuration changes to the Claude application environment via malicious packages or scripts.
avatar
Hrushikesh Badgujar@H3AD
XQL - Cortex Detections
27 days ago
101
Detects PEEP Secure Preferences integrity-hash forgery (protection.macs/super_mac) and known PEEP persistence scripts (patch_secure_prefs.ps1, install_silent.ps1, force_enable.ps1), anchored to actual Chrome/Edge profile paths rather than generic terms like 'protection' or 'developer_mode' that appear in unrelated admin tooling.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
404
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
004
Detects outbound network connections to 'registry.npmjs.org' originating from 'node' or 'bun' processes. This behavior may indicate an attempt to exfiltrate data, interact with malicious packages, or perform credential harvesting via npm tokens during execution.
avatar
Hrushikesh Badgujar@H3AD
avatar
Detections.ai Community
27 days ago
101
Detects outbound network connections to 'registry.npmjs.org' originating from 'node' or 'bun' processes. This behavior may indicate an attempt to exfiltrate data, interact with malicious packages, or perform credential harvesting via npm tokens during execution.
avatar
Hrushikesh Badgujar@H3AD
XQL - Cortex Detections
27 days ago
101
This rule identifies potential command-and-control (C2) beaconing behavior by detecting repetitive, consistent connections (low jitter) to public IP addresses over common TLS ports (443, 8443, 4443, 9443) from processes that do not have a known history of connecting to those destinations. It establishes a baseline of historical connections to filter out legitimate traffic and uses a statistical analysis of connection intervals to highlight suspicious, non-human-like automated communication patterns.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
24 days ago
000
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
This rule detects potential Command and Control (C2) beaconing activity by identifying periodic outbound network connections from suspicious or non-browser processes. It analyzes the time deltas between successful network connections; if the standard deviation of these intervals is low (indicating consistent timing) and a sufficient number of connections occur, it flags the behavior as a potential C2 heartbeat.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
22028
Page 376 of 1870