Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a single process accessing multiple distinct sensitive files related to cryptocurrency wallets, SSH keys, or seed phrases within a short duration. This pattern of bulk file access is highly indicative of automated credential harvesting modules like those found in the CRPx0 malware family.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
404
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
304
Detects unauthorized modifications to critical authentication-related configuration files and registry keys. Specifically monitors changes to LSA security packages and notification packages on Windows systems, as well as PAM configuration file modifications on Linux systems, when performed by unsigned or untrusted processes outside of known installer activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
103
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
103
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
003
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
This rule detects unauthorized attempts to modify CrowdStrike Falcon sensor exclusion registry keys or commands involving DLL loading techniques that may indicate evasion preparation, specifically referencing potential FalconFlank-related activities. It filters out legitimate management activity from known service accounts, SCCM, and the CrowdStrike Falcon agent itself.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
6012
Detects anomalous network traffic patterns characterized by rapid domain rotation, where multiple distinct domains resolve to a known set of IronToll C2 infrastructure IP addresses within a short timeframe (48 hours). Added an explicit 2-day lookback window — the original query had no time bound at all, so every scheduled run re-scanned the table's entire retention period and would keep re-surfacing the same historical match indefinitely instead of only genuinely recent activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
This rule monitors network traffic from internal devices and security logs for communication with a curated list of known malicious or suspicious scanner IP addresses, indicating potential reconnaissance or probing activity by external actors.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
303
This rule monitors network traffic from internal devices and security logs for communication with a curated list of known malicious or suspicious scanner IP addresses, indicating potential reconnaissance or probing activity by external actors.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
103
Detects a potential Kerberoasting attempt by identifying a single user or IP requesting multiple RC4-encrypted Ticket Granting Service (TGS) tickets for distinct service accounts within a short timeframe. Kerberoasting involves requesting TGS tickets for service accounts, which are then used for offline brute-force cracking of the service account's password hash.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
4013
Detects anomalous remote interactive or network logons where the specific account and remote host/IP combination has not been observed in the previous 14 days. The rule correlates these new login events with subsequent process execution on the destination host within a short window (5 minutes) to identify potential lateral movement where an adversary uses valid credentials to log in and immediately execute commands.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
303
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
27 days ago
001
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
avatar
Ankit Mehta@Secvyn
Defender - KQL
27 days ago
001
This rule monitors DeviceNetworkEvents for outbound connections to a list of known malicious or suspicious IP addresses. This activity is indicative of potential command and control (C2) communication or unauthorized data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
27 days ago
001
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
201
This rule monitors DeviceNetworkEvents for outbound connections to a list of known malicious or suspicious IP addresses. This activity is indicative of potential command and control (C2) communication or unauthorized data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
101
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
103
Page 380 of 1870