Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects unauthorized access to DPAPI master key files located in the Windows user profile (%APPDATA%\Microsoft\Protect\). This activity is commonly associated with infostealers attempting to decrypt browser-stored credentials (cookies, passwords) by manually accessing the master key files after exfiltrating encrypted data stores.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects DNS resolution attempts for newly registered or suspicious top-level domains (e.g., .xyz, .top, .live) that mimic corporate Identity Provider (IdP) or Single Sign-On (SSO) login portals. This behavior is characteristic of Adversary-in-the-Middle (AiTM) phishing kits like EvilProxy or Tycoon2FA, intended to capture user session tokens. Note: This rule monitors for initial domain contact and should be correlated with subsequent authentication logs to identify potential session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects unauthorized access to common browser credential storage files (Login Data, Cookies, Web Data, Local State) by processes other than standard web browsers. This rule identifies potentially malicious activity by filtering for rare or unsigned binaries executing from common staging directories (Temp, Downloads) or accessing browser files shortly after the process launch, which is a common behavior pattern for info-stealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule correlates endpoint security alerts for popular information-stealer malware (Lumma, StealC, Vidar, RedLine, Acreed, Atomic Stealer) with subsequent successful cloud identity authentication events from the same user account. The correlation window is set to 72 hours following an endpoint infostealer detection, which suggests potential account takeover or unauthorized access facilitated by credentials stolen from a compromised endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the startup or configuration of the WebClient service, commonly associated with WebDAV redirection, followed within 15 minutes by a process (e.g., control.exe, rundll32.exe, svchost.exe) interacting with a WebDAV-style UNC path. This behavioral pattern is indicative of attackers, such as the Star Blizzard group, abusing built-in Windows functionality to facilitate credential theft or remote file execution via malicious WebDAV shares.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
Detects a multi-stage exfiltration sequence consisting of: (1) bulk file archival/compression using common utilities, (2) suspicious OAuth grant or service principal authorization, and (3) abnormal network egress volume to common ports. This pattern suggests an adversary is preparing data, establishing or leveraging an identity/application for cloud access, and subsequently exfiltrating data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
203
Detects the LEMURLOOT ASP.NET web shell deployed by Cl0p following exploitation of CVE-2023-34362 in MOVEit Transfer
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
103
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
Detects the creation of a new Windows service where the service executable is located in potentially suspicious directories such as \Temp\, \Users\Public\, \AppData\, or \ProgramData\. Attackers often use these locations to drop and execute malicious payloads or persistence mechanisms while bypassing standard software installation security controls.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
8 days ago
101
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
avatar
Arnold Chan@slaz
avatar
SlimKQL
16 days ago
4012
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
2010
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
106
Detects anomalous child process execution (e.g., cmd.exe, powershell.exe) by the Microsoft Exchange IIS worker process (w3wp.exe) or the creation of .aspx files in Exchange web directories. This behavior is highly indicative of post-exploitation activity, such as web shell deployment, frequently observed in attacks targeting vulnerabilities like ProxyShell and ProxyLogon.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
007
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
102
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
202
This rule monitors for known suspicious RPC interface and function calls indicative of post-exploitation activities. It specifically targets RPC patterns used for lateral movement (e.g., PsExec, wmiexec, dcomexec), authentication coercion (e.g., PetitPotam, PrinterBug), and credential theft (e.g., DCSync, SAMR enumeration) by filtering on specific interface UUIDs and operation numbers.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
18 days ago
2020
Detects a file named dnsapi.dll created/modified outside System32/SysWOW64/WinSxS (the only legitimate locations for the real system DLL). Now requires the file to BOTH land in one of the known NeedyMantis sideload staging folders AND match the published 3448-byte spoofed-config size -- previously the size check alone could match unrelated dnsapi.dll copies anywhere on disk; requiring both signals together removes that bypass.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
002
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
002
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
002
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
002
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
003
Page 38 of 1870