Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the GoCaracal lightweight implant performing process injection by identifying combinations of remote process memory allocation (VirtualAllocRemoteApiCall), memory writing (WriteProcessMemoryRemoteApiCall), and remote thread creation (CreateRemoteThreadApiCall) associated with specific suspicious filenames. It also monitors command-line activity for injection-related flags.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects a pattern of multiple failed authentication attempts (brute force) from an external IP address followed by a successful authentication event on remote access services such as RDP, VPN, or NTLM. The rule filters for non-private IP addresses and flags successes occurring outside of standard business hours.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
403
Detects instances where base64-encoded PHP code, obfuscated behind a 'data:image/gif;base64' MIME type prefix, is written to the disk as a .php file or initiated by web server processes. This pattern is commonly used in file upload bypass attacks to execute arbitrary code.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
503
Detects modifications to the 'metrics_interval' registry value within the 'Software\SynapseAgent' key. This activity suggests configuration changes to the SynapseAgent, which could indicate tampering with agent telemetry or polling frequency.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
203
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects the execution of processes named 'ProManager.exe' or 'ProManagerServicedc894.exe', which may be indicative of unauthorized software or potentially malicious activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects anomalous registry enumeration or modification activities targeting software uninstallation registry keys (Run/Uninstall). By monitoring for multiple subkey accesses by processes not associated with standard software management tools (like MsiExec or explorer), this rule identifies potential reconnaissance or software discovery patterns indicative of malicious activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects Node.js or Electron processes executing from suspicious paths (e.g., Temp, Roaming) while interacting with web browser credential files or executing commands consistent with automated credential dumping tools.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
104
Detects instances where common web browsers (msedge, chrome, firefox, iexplore, brave, opera) are initiated with a command line containing a specific suspicious domain 'llove-kitchens.com', indicating potential interaction with a malicious web resource.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
405
Detects interaction with known infrastructure associated with the PREY-0058 campaign, which utilizes Adversary-in-the-Middle (AiTM) phishing lures mimicking passkey or MFA registration pages to target Microsoft 365 and other SaaS applications.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
28 days ago
001
Detects actions taken by Windows Defender malware detection engines
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
109
Page 390 of 1870