Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects Java-based Metasploit/Meterpreter payload files (.class/.jar) dropped post-exploitation, as observed following PaperCut RCE exploitation chain
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
26 days ago
000
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
avatar
Arnold Chan@slaz
Defender - KQL
26 days ago
100
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
000
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
26 days ago
000
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
000
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
000
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
26 days ago
100
Detects unauthorized processes (e.g., cmd.exe, powershell.exe, node.exe) accessing sensitive web browser files like 'Login Data' or 'Cookies' in common browser directories. This behavior is indicative of credential theft or data exfiltration attempts.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Detects unauthorized processes (e.g., cmd.exe, powershell.exe, node.exe) accessing sensitive web browser files like 'Login Data' or 'Cookies' in common browser directories. This behavior is indicative of credential theft or data exfiltration attempts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Detects Windows Application Error events where the faulting module is 'nvoglv64.dll'. This is indicative of a crash in the NVIDIA OpenGL/Vulkan user-mode driver, which may be associated with the exploitation of the GreenSection shared-memory corruption vulnerability.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
1 month ago
4021
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Monitors Active Directory Certificate Services (AD CS) for an unusual volume of certificate requests from a single requester within a short timeframe. This behavior is indicative of enumeration or exploitation activity by tools such as Certify or Certipy, which often perform rapid certificate requests to identify vulnerable templates or request certificates for unauthorized identities.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
9014
Detects offreg.dll (Windows Offline Registry Library) being loaded by a process running outside the standard System32/SysWOW64 directories and that is not a known Windows registry-management host process, excluding Malwarebytes' own bundled private copy of the DLL. PrettyPrague uses this library to read the SAM/LSA hive and derive boot-key material outside normal registry API paths. Scoped to the loading process's directory and identity rather than any specific PoC binary name.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
1 month ago
7018
Detects direct file access attempts to critical Windows registry hive files (SAM, SECURITY, SYSTEM, SOFTWARE) on disk. These files contain sensitive system and credential information, and direct access is frequently used by adversaries to perform offline credential dumping.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
1019
This rule detects network connections and DNS queries associated with the QTFY proxy infrastructure, including specific domains, known proxy management system IPs, and suspicious IP ranges. This behavior is indicative of command and control (C2) activity utilizing proxy services to obfuscate traffic.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
This rule detects network connections and DNS queries associated with the QTFY proxy infrastructure, including specific domains, known proxy management system IPs, and suspicious IP ranges. This behavior is indicative of command and control (C2) activity utilizing proxy services to obfuscate traffic.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
000
This rule detects network connections and DNS queries associated with the QTFY proxy infrastructure, including specific domains, known proxy management system IPs, and suspicious IP ranges. This behavior is indicative of command and control (C2) activity utilizing proxy services to obfuscate traffic.
avatar
Arnold Chan@slaz
Defender - KQL
26 days ago
000
The detection rule identifies network connections to 'dauntingmoon.online' specifically hitting '/api/verification/init' or '/api/verification/check' paths. It validates that both 'session' and 'link_id' query parameters are present in the request. This pattern is indicative of a specific adversary beaconing or command and control (C2) callback mechanism involving session-based authentication or handshake steps with a remote server.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
101
The detection rule identifies network connections to 'dauntingmoon.online' specifically hitting '/api/verification/init' or '/api/verification/check' paths. It validates that both 'session' and 'link_id' query parameters are present in the request. This pattern is indicative of a specific adversary beaconing or command and control (C2) callback mechanism involving session-based authentication or handshake steps with a remote server.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
001
This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Page 392 of 1870