Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects presence of multiple ShieldCrash CVE-2026-69414 PoC Visual Studio project/solution build artifacts indicating exploit tooling staging
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects high-frequency file creation, modification, or renaming activity involving files with the specific '.df_win' extension, likely indicative of mass encryption activity or automated ransomware behavior. The rule excludes known backup and security software processes to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects high-frequency TCP/445 connection attempts (a 'connect sweep') characteristic of automated SMB share enumeration, which is commonly used for lateral movement reconnaissance. The rule triggers when a threshold of 40 connection requests occurs from a single source within a 30-second window, specifically targeting SMB-related lateral movement behaviors.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
002
Detects high-frequency TCP/445 connection attempts (a 'connect sweep') characteristic of automated SMB share enumeration, which is commonly used for lateral movement reconnaissance. The rule triggers when a threshold of 40 connection requests occurs from a single source within a 30-second window, specifically targeting SMB-related lateral movement behaviors.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
002
Detects PowerShell scripts that utilize native PowerShell Identity modules to request Kerberos tickets.
This behavior is typically seen during a Kerberos or silver ticket attack. A successful execution will output the SPNs for the endpoint in question.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
25 days ago
000
Detects repeated attempts to delete Volume Shadow Copies using WMIC. This is a common technique used by ransomware and other malware to prevent system recovery and inhibit forensic investigations. The rule filters out known backup agents and service accounts and identifies patterns where multiple distinct deletions occur within a 5-minute window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
102
Detects repeated attempts to delete Volume Shadow Copies using WMIC. This is a common technique used by ransomware and other malware to prevent system recovery and inhibit forensic investigations. The rule filters out known backup agents and service accounts and identifies patterns where multiple distinct deletions occur within a 5-minute window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects high volumes of file renaming activities involving files with the .df_win extension. This pattern is often indicative of ransomware-like behavior where mass renaming occurs as part of an encryption process, impacting multiple directories.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
102
Detects high volumes of file renaming activities involving files with the .df_win extension. This pattern is often indicative of ransomware-like behavior where mass renaming occurs as part of an encryption process, impacting multiple directories.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
102
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
avatar
Ankit Mehta@Secvyn
Defender - KQL
30 days ago
002
Detects indicators of the ProRAM malware dropper, specifically identifying the download of 'sideload.exe' from an external IP or the presence of file artifacts related to its staging process in %TEMP% and %LOCALAPPDATA% directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
005
Detects the loading of the ProRAM implant DLL (somkernl.dll) when initiated by known sideloading carriers such as 360speedld.exe or SoftupNotify.exe, which are signed utilities frequently abused for this purpose.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
005
Detects the presence of known artifacts associated with the GreenSection proof-of-concept exploit, including the source code file 'GreenSection.cpp', a specific driver crash dump 'nvoglv64.dmp', and a associated unique GUID. These files are indicators that an actor has staged exploit materials on the system.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
1013
Detects the addition of a 'msDS-KeyCredentialLink' attribute to an Active Directory object (Event 5136), which is indicative of the Shadow Credentials attack vector, followed by a successful PKINIT authentication (Event 4768) for that account. This combination suggests that an adversary has successfully established persistent access using a forged or unauthorized device credential and is now utilizing it for authentication.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
33011
Detects the starting of the RemoteRegistry service via command-line utilities such as 'sc.exe' or 'net.exe'. This service is often started by adversaries to facilitate remote access to the Windows Registry for reconnaissance or enumeration of logon sessions.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
1 month ago
1038
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to execute processes, particularly when a remote node target is specified or when using common WMI process creation arguments. This pattern is commonly used by adversaries for lateral movement and remote code execution while attempting to blend into administrative activity. Legitimate management tools have been excluded from the scope to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
001
Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
001
Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
001
Detects anomalous system reconnaissance activity performed using WMIC or PowerShell Get-WmiObject commands. The rule tracks distinct command-line executions per device and flags hosts where three or more unique reconnaissance commands are executed within a short timeframe, which is indicative of an adversary enumerating system configuration, hotfixes, or hardware details.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
001
Detects anomalous system reconnaissance activity performed using WMIC or PowerShell Get-WmiObject commands. The rule tracks distinct command-line executions per device and flags hosts where three or more unique reconnaissance commands are executed within a short timeframe, which is indicative of an adversary enumerating system configuration, hotfixes, or hardware details.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
001
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
101
Page 387 of 1870