Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects unauthorized devices or processes attempting to communicate with the Telegram Bot API (/sendMessage or /sendDocument) and monitors for credential-related terms within the request metadata. This often indicates the use of Telegram as a command-and-control (C2) channel for data exfiltration or credential theft.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
102
Detects unauthorized devices or processes attempting to communicate with the Telegram Bot API (/sendMessage or /sendDocument) and monitors for credential-related terms within the request metadata. This often indicates the use of Telegram as a command-and-control (C2) channel for data exfiltration or credential theft.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
102
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
001
Detects suspicious service installation patterns involving WmiPrvSE, common in lateral movement techniques.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
001
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
001
Detects remote service creation consistent with PsExec-style lateral movement by correlating network logons (Type 3) with subsequent service installations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
101
Detects remote service creation consistent with PsExec-style lateral movement by correlating network logons (Type 3) with subsequent service installations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
001
Detects post-exploitation persistence artifacts on Windows endpoints consistent with abuse of CVE-2026-18577.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
001
Detects installation of specific suspicious or known helper services, often associated with persistence or proxying.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
001
Detects installation of specific suspicious or known helper services, often associated with persistence or proxying.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
001
Detects a DLL created or modified directly under C:\Windows\System32 that is then loaded into a process within 30 minutes of its creation. This creation-to-load temporal correlation is a durable indicator of a dropped-and-loaded malicious module (as used by the HardBreacher/SolidSnake exploit chain), independent of the DLL's filename. Signer/trust correlation intentionally omitted (DeviceFileCertificateInfo not part of this environment's ingested telemetry).
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
1 month ago
6014
This rule detects modifications, creation, or renaming of the Windows hosts file located at 'C:\Windows\System32\drivers\etc\hosts'. Adversaries often modify this file to redirect network traffic, facilitate phishing, or prevent security tools from communicating with update or telemetry servers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects the execution of known WinProtector rogueware binaries. These files often present fake 'threat detected' popups to coerce users into paying for fraudulent software and are frequently bundled with other malware, such as Sality.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
This rule monitors for suspicious activity targeting security software and host security configurations. It detects the termination of security-related processes using 'taskkill' or service management commands, the disabling of Windows Firewall via 'netsh', and the modification of critical Registry keys related to User Account Control (UAC), Registry editing access, and Task Manager functionality.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects malicious activity patterns characteristic of Sality or similar rootkits, which involve disabling endpoint protection mechanisms (AV/Firewall) in conjunction with kernel-mode driver installation or hooking operations to persist and hide malware activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
This rule detects potential credential and keystroke theft by identifying the installation of a Windows hook (SetWindowsHookEx) followed within 30 minutes by file access to sensitive browser credential stores (Login Data, key4.db, etc.) by the same process on a single device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects the Sality malware secondary loader creating a new thread within the same infected process, a technique known as self-injection, used to execute decrypted payloads. The rule specifically looks for 'CreateRemoteThreadApiCall' events where the initiating process ID matches the target process ID and correlates this behavior with the creation of mutexes associated with the Sality malware family.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
This rule detects potentially malicious executables associated with Sality malware that consistently launch shortly after system startup across multiple boot sessions. It correlates boot events with process execution events within a 10-minute window post-startup to identify programs exhibiting persistence behavior across at least two separate boot instances.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects a host performing high-volume outbound network scanning (connecting to 10 or more distinct public IP addresses within 15 minutes) followed by the execution of an executable file created in common suspicious directories (AppData, Temp, Downloads, or Users/Public) within a short window (10 minutes after the scan). This pattern is indicative of a compromised host scanning for lateral movement opportunities or propagation targets, followed by the deployment of malicious tooling.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
This rule monitors for two indicators of potentially self-propagating malware: the creation of autorun.inf files on removable or network-mapped drives combined with active SMB network connections (suggesting worm propagation), and the rapid creation of multiple unique executable files across multiple devices (suggesting an outbreak or worm activity).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects execution and file activity associated with the XRed backdoor, which masquerades as 'Synaptics.exe' by running from the non-standard 'C:\ProgramData\Synaptics\' directory instead of authorized system paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
27 days ago
000
Page 398 of 1870