Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
202
Detects the use of the native Windows registry utility 'reg.exe' to import configuration files (install.reg) related to the Radmin remote access software, specifically targeting the security settings registry path.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
This rule detects potentially malicious PowerShell execution patterns involving hidden windows, administrative elevation via 'Start-Process -Verb RunAs', and the targeting or execution of rsetup64.exe within specific system paths. It also flags execution chains where 'net session' commands, often used for discovery or local privilege verification, are piped to null and followed by or initiate the same target executables, suggesting lateral movement or persistence attempts.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
202
The following analytic detects shells, scripting engines, and common post-exploitation utilities spawned as child processes of smsexec.exe.
smsexec.exe is the core SCCM SMS Executive service process and has no legitimate reason to launch interactive shells or scripting interpreters.
An attacker who plants a malicious adsource.dll in the SCCMProvider bin\X64 directory will obtain code execution in the SCCM service context, typically resulting in a SYSTEM-level child process being spawned under smsexec.exe.
If confirmed malicious, this activity represents successful exploitation of the SCCM SMS Executive service and should be treated as a full host compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
103
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects nm_host.exe (PEEP native messaging host binary) spawned by Chrome/Edge, tightened to require either the known PEEP extension ID in the native-messaging invocation command line or the distinctive com.peep.lab host path.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects the execution of command interpreters (PowerShell, CMD, WindowsTerminal) spawned by common user-facing applications (Explorer, WindowsTerminal, DLLHost) where the command line arguments contain keywords associated with automated human verification (e.g., CAPTCHA, bot detection) and suspicious download/execution patterns (e.g., iex, base64). This behavior is characteristic of malicious automated scripts or malware attempting to bypass security challenges via interactive shells.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
7114
Detects instances where common web browsers (msedge, chrome, firefox, iexplore, brave, opera) are initiated with a command line containing a specific suspicious domain 'llove-kitchens.com', indicating potential interaction with a malicious web resource.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
304
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden windows) initiated by mshta.exe, excluding instances where a .ps1 script file is involved. This pattern often indicates attempts to bypass execution policy or run obfuscated payloads in memory, which is a common behavior of malicious HTA files.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
104
This rule detects the execution of potentially malicious files (executables, scripts) from user-writable directories (Downloads, AppData, Desktop) where the file appears to be related to a ZIP archive recently downloaded or extracted by an archive handler or browser. It correlates process execution events with file creation events from ZIP archives to identify potential user-execution of malicious payloads delivered via ZIP files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
204
Detects successful logon events (Event ID 4624) utilizing Schannel (TLS client certificate) or PKU2U (peer authentication) logon processes. This behavior may indicate an attacker using forged or stolen certificates to authenticate against a system, potentially bypassing Kerberos-based authentication monitoring.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
1308
This rule monitors DeviceNetworkEvents for any outbound network connections made to the specific IP address 79.133.56.90. This address is identified as malicious or a known indicator of compromise (IoC) and may indicate command and control (C2) communication or unauthorized data transfer originating from a managed endpoint.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
101
This rule monitors for indicators of compromise (IOCs) and behavioral patterns associated with the Lazarus Group's 'Operation Dream Job' campaign. It tracks known malicious hashes, domains, and IP addresses, alongside suspicious activities such as PDF viewer abuse, DLL side-loading, process injection, persistence mechanism creation (Registry/Scheduled Tasks), and recruitment-themed phishing lures.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
37084
This rule detects potential ransomware activity by correlating three distinct indicators: deletion of Volume Shadow Copies (using native Windows utilities), mass file modifications (>100 files in 15 minutes), and the creation or modification of files typically associated with ransom notes. The rule uses an inner join to ensure these events happen within a 30-minute window of each other on the same device.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects the execution of 'bun' during a Node.js package installation process (npm or node). This behavior can be indicative of a supply chain attack where malicious actors attempt to leverage alternative runtimes during the 'preinstall' phase or package installation to execute arbitrary code or bypass security controls typically associated with standard Node.js installations.
avatar
Arnold Chan@slaz
Defender - KQL
26 days ago
100
This rule detects potentially malicious command-line activity involving powershell.exe or mshta.exe that is initiated by a web browser process (chrome.exe, msedge.exe, firefox.exe, or iexplore.exe). It monitors for indicators such as encoded commands, usage of Invoke-Expression, download cradles, hidden window flags, and specific known IOCs, correlating these events with recent browser activity to identify potential drive-by download or browser-based exploitation attempts.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects network requests to unpkg.com or npmmirror for 'index.html' files directly under a package path. This behavior deviates from standard package management usage (which typically fetches tarballs or specific JavaScript modules) and is often associated with adversaries using npm packages as hosting infrastructure for phishing landing pages.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects anomalous outbound network connections from the Grafana MCP (Model Context Protocol) server process to internal private IP address ranges. The rule compares current network activity against a 14-day baseline to filter out known data sources, identifying potentially unauthorized lateral movement or internal network probing via server-side request forgery (SSRF) vulnerabilities.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects the use of 'schtasks.exe' to disable critical Windows Update or ExploitGuard Malware Removal tasks when initiated by 'LockAppHost.exe'. This behavior is highly irregular, as the LockAppHost process is typically associated with the Windows Lock Screen and should not be modifying security-related scheduled tasks.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects anomalous remote interactive or network logons where the specific account and remote host/IP combination has not been observed in the previous 14 days. The rule correlates these new login events with subsequent process execution on the destination host within a short window (5 minutes) to identify potential lateral movement where an adversary uses valid credentials to log in and immediately execute commands.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Page 395 of 1870