Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects Ruby source files containing a hardcoded RubyGems API key (rubygems_ prefixed token) used for unauthorized gem publish/push actions, as seen in the yardxabc889 package from the GemStuffer campaign
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
000
Detects N-able N-central Take Control remote session start/end events in the Windows Application log where the viewer identity is the default N-central support account 'MSP Support' / mspsupport@n-able.com, or the source/viewer IP matches known attacker infrastructure associated with active exploitation of CVE-2026-18577.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
This rule detects activities related to Tampermonkey (a popular browser extension for userscripts) or interactions with paste.sh, often used for hosting scripts or payloads. The rule monitors both process-level executions and network requests for these indicators, which may be associated with malicious script execution or browser-based credential or session theft.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
101
This rule detects activities related to Tampermonkey (a popular browser extension for userscripts) or interactions with paste.sh, often used for hosting scripts or payloads. The rule monitors both process-level executions and network requests for these indicators, which may be associated with malicious script execution or browser-based credential or session theft.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
001
Detects several potentially malicious activities related to Active Directory Certificate Services (AD CS). This includes high volumes of failed requests (potential enumeration), requests for sensitive templates (privilege escalation), and potential impersonation attempts using Subject Alternative Names (SANs). These activities are associated with AD CS abuse techniques.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
103
Detects the execution of processes named 'ProManager.exe' or 'ProManagerServicedc894.exe', which may be indicative of unauthorized software or potentially malicious activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Detects the use of 'schtasks.exe' to disable critical Windows Update or ExploitGuard Malware Removal tasks when initiated by 'LockAppHost.exe'. This behavior is highly irregular, as the LockAppHost process is typically associated with the Windows Lock Screen and should not be modifying security-related scheduled tasks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Detects malicious network connections, file downloads, or process execution associated with the REVSTEALER malware campaign, which utilizes hijacked YouTube channels to distribute fake game-cheat videos that lure users into downloading 'resightloader.exe' from specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
103
Detects the loading of registry hives using the 'reg load' command. This technique is often associated with adversary attempts to manipulate the Windows registry, access sensitive data, or establish persistence, particularly when followed by actions executed in the SYSTEM context from the same process lineage.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
207
This rule detects the creation of a scheduled task using 'schtasks.exe' where the task name matches commonly abused names such as 'WinUpdate.exe', 'SoftManager.exe', or 'LockAppHost.exe'. These names are frequently used by adversaries to masquerade as legitimate Windows processes to achieve persistence.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
203
Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
103
Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
003
Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
003
Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
103
Page 397 of 1870