Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
001
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
101
Detects remote administration activity via Windows Management Instrumentation (WMI) originating from a host that has no recorded history of performing such actions within the previous 30 days. This includes the use of wmic.exe for remote nodes, Invoke-WmiMethod, or WmiPrvSe.exe spawning common command-line interpreters or utilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
001
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
001
Detects high-frequency, automated web scraping behavior targeting product catalog pages, indicative of content harvesting for site replication. The rule monitors IIS logs for non-browser user agents (e.g., Python, curl, Scrapy) performing rapid, multi-page requests within a short duration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
001
Detects high-frequency, automated web scraping behavior targeting product catalog pages, indicative of content harvesting for site replication. The rule monitors IIS logs for non-browser user agents (e.g., Python, curl, Scrapy) performing rapid, multi-page requests within a short duration.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
001
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
101
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
28 days ago
001
Detects unauthorized devices or processes attempting to communicate with the Telegram Bot API (/sendMessage or /sendDocument) and monitors for credential-related terms within the request metadata. This often indicates the use of Telegram as a command-and-control (C2) channel for data exfiltration or credential theft.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
203
Detects instances where the NW.js (Node-Webkit) framework binaries (nw.exe, node.exe) spawn common command-line interpreters or script-hosting utilities (e.g., cmd.exe, powershell.exe, wscript.exe) while executing associated application files like main.js or nw.pak. This behavior is indicative of potential exploitation of a browser-based application to gain shell access or execute arbitrary code on the host system.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
108
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
003
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
203
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
003
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
003
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
203
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
203
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
203
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
203
This rule detects potentially malicious behavior associated with Microsoft Office applications, such as Word, initiating suspicious WebDAV network connections, dropping executable or sensitive files, or spawning known LOLBAS processes (rundll32, explorer, regsvr32) from suspicious directories like Temp or WebDAV paths. It also includes a blocklist for known malicious file hashes associated with these patterns.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
28 days ago
001
This rule detects potentially malicious behavior associated with Microsoft Office applications, such as Word, initiating suspicious WebDAV network connections, dropping executable or sensitive files, or spawning known LOLBAS processes (rundll32, explorer, regsvr32) from suspicious directories like Temp or WebDAV paths. It also includes a blocklist for known malicious file hashes associated with these patterns.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
28 days ago
101
This rule detects potential COM hijacking of the CLSID InprocServer32 registry keys or unauthorized loading/creation of the 'EhStoreShell.dll' file. These behaviors are common indicators of persistence mechanisms or DLL side-loading where attackers redirect legitimate system calls to malicious code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
101
Page 388 of 1870