Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
202
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
302
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
This rule detects modifications to Group Policy Objects (GPO) or Microsoft Entra (formerly Azure AD) policies that weaken established security controls. For GPO, it monitors Event ID 5136 for changes to security-relevant attributes (e.g., disabling firewall or real-time monitoring) in Active Directory. For Entra, it monitors audit logs for administrative operations that reduce security posture, such as disabling MFA, lowering authentication trust, or deleting Conditional Access policies. It includes filters to exclude legitimate, documented change management activities.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects msiexec.exe executing from the Temp directory with suspicious command-line arguments (such as hidden windows) and spawning child processes like cmd.exe, tasklist.exe, or taskkill.exe. This behavior is often indicative of malicious installation scripts attempting to perform discovery or terminate security processes while remaining stealthy.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
001
Detects indicators of the ProRAM malware dropper, specifically identifying the download of 'sideload.exe' from an external IP or the presence of file artifacts related to its staging process in %TEMP% and %LOCALAPPDATA% directories.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
004
Detect built in PowerShell cmdlet Disable-WindowsOptionalFeature, Deployment Image Servicing and Management tool.
Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
6014
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
The following analytic detects an unusual process execution pattern where a process running from C:\Windows\SysWOW64\ attempts to execute a binary from C:\Windows\System32\. In a typical Windows environment, 32-bit processes under SysWOW64 should primarily interact with 32-bit binaries within the same directory. However, an execution flow where a 32-bit process spawns a 64-bit binary from System32 can indicate potential process injection, privilege escalation, evasion techniques, or unauthorized execution hijacking.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
006
The detection rule identifies an suspicious process named 'msgbox.exe' attempting to interact with browser configuration files ('Secure Preferences') and activity directories ('stomp_ext'), while simultaneously invoking browser processes ('chrome.exe' or 'msedge.exe') with the '--restore-last-session' argument. This behavior is indicative of an adversary attempting to force-load a browser session or hijack browser state, potentially to steal session cookies or credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
101
Detects the creation of a scheduled task containing 'EdgeCore_AutoUpdate' in the command line using either schtasks.exe or Register-ScheduledTask. This pattern is often indicative of persistence mechanisms attempting to masquerade as legitimate update services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
101
This rule detects the concurrent existence of specific process names (calibre-launcher.dll or wint.exe) and a specific file (SysPr.prx) on a device, combined with network connections to a specific Cloudflare R2 bucket. This pattern is indicative of potential malware activity involving suspicious DLLs, file drop-offs, and communication with remote infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
101
This rule detects potential fileless execution by correlating network connections to a known suspicious domain (workers.dev) with subsequent PowerShell activity on the same device. The rule specifically looks for processes executing PowerShell commands involving Base64 decoding, ChaCha20 decryption, or Assembly.Load, occurring within a 10-minute window of the network connection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
101
This rule detects network connections initiated by non-browser processes to domains commonly associated with software activation tools (e.g., massgrave.dev, activated.win). These domains are frequently used to download scripts or binaries related to unauthorized license activation, which may represent potential security risks or policy violations.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
10014
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
202
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
102
Detects the installation or execution of known remote access tools (RMM) from suspicious parent processes (browsers, archives) or from user-writable directories (Temp, Downloads). This behavior is characteristic of initial access and staging activities performed by ransomware operators or Initial Access Brokers (IABs). The rule excludes known IT-managed deployment paths and signed binaries used by the organization.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
202
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
202
Page 393 of 1870