Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects anomalous authentication behavior where a user account utilizes the same authentication session (LogonId) or material to authenticate across multiple distinct destination hosts in a short timeframe. This rule monitors for both NTLM (Type 3) and Kerberos (TGS/TGT) events, which are indicative of lateral movement techniques such as Pass-the-Hash or Pass-the-Ticket.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
103
This rule detects the presence of files or process execution events matching a known set of SHA256 hashes associated with the BlueMoon malware family. The detection covers both file system events and process creation events.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
29 days ago
202
This rule detects the presence of files or process execution events matching a known set of SHA256 hashes associated with the BlueMoon malware family. The detection covers both file system events and process creation events.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
202
This rule detects the creation of a specific mutex named 'GlobolID-4465173'. Mutexes are often used by malware to ensure that only a single instance of the malicious process runs on an infected host, serving as a reliable indicator of compromise (IOC) for specific malware families or campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
000
This rule detects potential credential theft activity by monitoring for unauthorized access to sensitive browser-related credential files (e.g., Login Data, cookies.sqlite) or direct access to the LSASS process memory by non-standard browser processes. It further correlates these events with user sign-ins on previously unknown or unassociated devices within a short timeframe to identify potential account compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
102
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
Detects UNC3569/GRAYRABBIT shellcode combining call/pop self-location, PEB InLoadOrderModuleList walk, and the specific XOR-then-ROR8 export-name hashing loop observed in the GRAYRABBIT loader chain, requiring multiple distinctive elements together to reduce false positives on generic shellcode idioms
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
This rule detects the termination of critical security software processes (e.g., antivirus agents) by a process that has recently acquired SeDebugPrivilege. This behavior is indicative of a malicious actor attempting to disable endpoint security controls to evade detection.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
103
Detects Rust-compiled executables exhibiting C2-capable characteristics consistent with backdoors dropped on compromised JFrog Artifactory servers
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
001
Detects network communication with Google Sheets API endpoints that contain specific indicators of C2 behavior, such as suspicious User-Agents, specific spreadsheet cell references, or input options characteristic of automated data exfiltration or command retrieval.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
003
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
103
Detects a command shell (cmd.exe, powershell.exe, powershell_ise.exe, pwsh.exe) created with a SYSTEM SID whose immediate parent process is a POSITIVELY IDENTIFIED non-SYSTEM account running at Low/Medium integrity. Excludes known-benign SYSTEM-spawning binaries and blank-parent scheduled-task/service noise confirmed via live telemetry and attached evidence logs, and drops the prior TokenElevationTypeFull branch which mostly matched routine UAC-elevated admin activity rather than an actual SYSTEM token.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
1 month ago
11025
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
205
Detects network connections from Windows hosts to known IP addresses and domain names associated with the exploitation infrastructure used in CVE-2026-18577, targeting N-able N-central servers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
905
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
205
Detects anomalous child process execution (e.g., cmd.exe, powershell.exe, whoami) by PaperCut application processes (java.exe, pc-app.exe, PCClient.exe), which is indicative of post-exploitation activity following an authentication bypass and remote code execution chain against PaperCut NG/MF.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
004
Matches known RedTail malware payloads and staging scripts by exact SHA-256 hash equality
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
001
Matches known RedTail malware payloads and staging scripts by exact SHA-256 hash equality
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
001
Matches known RedTail malware payloads and staging scripts by exact SHA-256 hash equality
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
001
Detects PowerShell processes initiating network connections to known public DNS-over-HTTPS (DoH) providers over port 443. This behavior is often associated with efforts to bypass standard organizational DNS logging and security controls by tunnelng DNS queries through encrypted HTTPS traffic.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
8020
Detects the execution of 'charmap.exe' from the Syswow64 directory where the process hierarchy indicates suspicious activity. The detection identifies a chain where PowerShell spawns 'conhost.exe', which in turn spawns a process from a temporary directory (interpreted as a renamed AutoIT executable) that then launches 'charmap.exe'. This pattern is indicative of a multi-stage obfuscated execution flow often used in malware dropper scenarios to bypass standard monitoring.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
25 days ago
000
Page 381 of 1870