Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects an exploitation chain originating from a Chrome browser process, characterized by the execution of an anomalous child process followed by the creation of an executable file named 'chrome_cleanup.exe' within a short time window. This sequence is indicative of multi-stage exploitation, involving remote code execution via browser vulnerability and subsequent privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
3012
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
4018
This rule detects potential credential stuffing attacks by monitoring high-volume authentication attempts against web application login endpoints. It specifically flags scenarios where a high number of unique source IP addresses interact with a login endpoint (e.g., /login, /signin) within a short window, which is characteristic of automated, distributed credential stuffing tools using proxy networks to rotate IPs.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects HTTP requests containing common web exploit patterns (SQLi, XSS, RCE) that exhibit characteristics of automated, mutating payload generation often utilized in AI-assisted fuzzing or vulnerability scanning tools. The rule monitors for encoded, obfuscated, or highly varied payload syntax within URI query strings.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects anomalous outbound lateral movement attempts where a single source host initiates WinRM connections (ports 5985/5986) to an unusually high number of distinct destination hosts within a short timeframe, which is often indicative of automated credential propagation or internal scanning by an adversary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
This rule detects a high frequency of SMB (port 445) connection attempts from a single internal source host to a large number of distinct internal destination hosts within a short timespan. This activity is indicative of internal network scanning, host discovery, or automated lateral movement attempts using SMB.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
Detects web requests targeting sensitive Jenkins/CI-CD administrative and build-triggering endpoints, such as /script, /manage, and /job/*/build. These paths are high-value targets for reconnaissance and automated exploitation efforts. This rule identifies potentially malicious activity by monitoring for access to these specific paths, which should be correlated with frequency and source data to differentiate automated scanning from authorized administrative or system activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
This rule detects unauthorized attempts to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. It monitors for common post-exploitation tools (such as procdump, mimikatz, nanodump, and sqldumper) or built-in Windows techniques (using rundll32.exe with comsvcs.dll) that are typically used to extract sensitive credential material from process memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects PowerShell processes initiated with command-line arguments that indicate obfuscation (e.g., -enc, -encodedCommand) or attempts to download or execute external content (e.g., IEX, Net.WebClient, Invoke-WebRequest). This pattern is commonly observed during the initial execution of malicious payloads or tool delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects potential lateral movement by identifying NTLM authentication (Logon Type 3) to administrative network shares (ADMIN$, C$, IPC$) or high-frequency access to multiple hosts by the same user, which may indicate credential abuse or lateral movement attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects PowerShell processes initiated with command-line arguments that indicate obfuscation (e.g., -enc, -encodedCommand) or attempts to download or execute external content (e.g., IEX, Net.WebClient, Invoke-WebRequest). This pattern is commonly observed during the initial execution of malicious payloads or tool delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the creation of suspicious Windows services associated with remote execution tools like PsExec, PAExec, or custom tools that leverage SMB administrative shares (ADMIN$, IPC$). The rule correlates the service creation event (Event ID 7045, 4697) with preceding network connection attempts to SMB shares, and subsequent service termination or state change events within a short timeframe, which is a pattern characteristic of remote lateral movement and command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the use of common PowerShell techniques designed to bypass the Antimalware Scan Interface (AMSI). These techniques involve manipulating internal PowerShell objects like AmsiUtils or amsiInitFailed, or using reflection to locate and modify AMSI memory structures to disable scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects the initiation of a new process where the effective user context is SYSTEM, but the originating process was launched by a non-privileged user account. This behavior is indicative of token manipulation techniques such as token impersonation or theft (e.g., via DuplicateTokenEx or ImpersonateLoggedOnUser) to escalate privileges to SYSTEM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects the use of native Windows utilities (vssadmin.exe, wmic.exe, wbadmin.exe, bcdedit.exe) to delete volume shadow copies, backup catalogs, or modify boot configuration data to inhibit system recovery, a common behavior observed during ransomware and wiper attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects suspicious PowerShell process creation patterns often associated with malicious activity. The rule identifies PowerShell execution invoked by common parent processes (like Office applications or scripting engines) or using highly suspicious command-line arguments such as encoded commands, hidden windows, or common download and execution patterns (e.g., IEX, WebClient).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the abuse of built-in Windows binaries 'regsvr32.exe' and 'msbuild.exe' for proxy execution. Specifically, it flags 'regsvr32.exe' loading remote scriptlets via HTTP and 'msbuild.exe' processing project files containing inline tasks, which are common techniques used to execute arbitrary malicious code while bypassing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the abuse of built-in Windows binaries 'regsvr32.exe' and 'msbuild.exe' for proxy execution. Specifically, it flags 'regsvr32.exe' loading remote scriptlets via HTTP and 'msbuild.exe' processing project files containing inline tasks, which are common techniques used to execute arbitrary malicious code while bypassing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects suspicious PowerShell process creation patterns often associated with malicious activity. The rule identifies PowerShell execution invoked by common parent processes (like Office applications or scripting engines) or using highly suspicious command-line arguments such as encoded commands, hidden windows, or common download and execution patterns (e.g., IEX, WebClient).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the use of native Windows utilities (vssadmin.exe, wmic.exe, wbadmin.exe, bcdedit.exe) to delete volume shadow copies, backup catalogs, or modify boot configuration data to inhibit system recovery, a common behavior observed during ransomware and wiper attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Page 39 of 1870