Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule detects potential DLL sideloading by monitoring known legitimate Windows binaries that are commonly abused to load malicious DLLs from non-standard directories (i.e., not System32, SysWOW64, or WinSxS). This activity is often associated with the TerminalFix / Lorem Ipsum Loader campaign.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
7 days ago
609
This rule monitors endpoint telemetry for indicators of compromise (IOCs) associated with known malicious activity. It checks for file creation, process execution, and network connections that match a defined list of malicious file hashes (SHA256, SHA1, MD5), C2 IP addresses, and malicious domains or URL patterns.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
2 days ago
102
This rule monitors endpoint telemetry for indicators of compromise (IOCs) associated with known malicious activity. It checks for file creation, process execution, and network connections that match a defined list of malicious file hashes (SHA256, SHA1, MD5), C2 IP addresses, and malicious domains or URL patterns.
avatar
Arnold Chan@slaz
Defender - KQL
2 days ago
302
This rule monitors endpoint telemetry for indicators of compromise (IOCs) associated with known malicious activity. It checks for file creation, process execution, and network connections that match a defined list of malicious file hashes (SHA256, SHA1, MD5), C2 IP addresses, and malicious domains or URL patterns.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
2 days ago
102
This rule detects successful network connections to known malicious IP addresses or the domain 'forgitlab.com', which are associated with the Azazel malware threat infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
2 days ago
102
Detects anomalous process execution and loopback network activity associated with the Model Context Protocol (MCP) 'exec_in_session' method. This pattern indicates an adversary potentially abusing the AI coding assistant's MCP server capabilities to execute arbitrary commands as a C2 channel.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
2 days ago
002
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
309
The following analytic detects the addition of a servicePrincipalName (SPN) containing invisible Unicode characters to an Active Directory computer object via Windows Security Event 5136.
This is the key indicator of the KerberLoss attack (CVE-2026-25177), where an attacker with write access to a machine account's SPN attribute injects a collision SPN that contains a Zero Width or other invisible Unicode character (e.g. U+200C Zero Width Non-Joiner).
LDAP's string preparation rules (RFC 4518) cause these characters to be ignored during uniqueness checking, allowing the write to succeed even when an identical SPN already exists on another machine account.
The Kerberos KDC, however, does not apply the same normalisation — it finds two accounts with matching SPNs and returns KDC_ERR_S_PRINCIPAL_UNKNOWN, causing a Kerberos denial-of-service or forcing clients to fall back to NTLM downgrade.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
SlimKQL
7 days ago
509
Detects when an AI agent or assistant process attempts to access sensitive local configuration or credential files (e.g., .aws/credentials, .env, id_rsa, service account keys, .netrc) that typically fall outside the scope of its intended function. This behavior is indicative of unauthorized access, potentially due to prompt injection or malicious exploitation of the agent's file system permissions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
2010
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
8010
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
608
Detects potential exploitation attempts targeting the vulnerable Oracle PeopleSoft PSEMHUB Environment Management Hub endpoint (associated with CVE-2026-35273 and UNC6240). The rule identifies suspicious bursts of POST requests where the URI path uses percent-encoding or mixed-case characters to evade Web Application Firewall (WAF) filtering.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
7023
Detects DNS resolutions to popular threat intelligence, reputation, and sandboxing APIs (e.g., VirusTotal, URLScan, AbuseIPDB) originating from non-browser processes on non-analyst workstations. This behavior may indicate an attacker programmatically querying these services to verify if their infrastructure, payloads, or IP addresses are flagged as malicious, or to conduct reconnaissance.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
13 hours ago
001
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
10020
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
1010
Detects unauthorized or suspicious use of the DsGetNCChanges (opnum 3) function on the DRSUAPI interface. This RPC method is commonly abused in DCSync attacks to replicate domain controller data, including sensitive password hashes, from an Active Directory environment.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
4 days ago
103
Detects activity associated with the MALFEX npm supply-chain campaign (also known as Overlord/movinlike). This rule performs a sweep for known malicious file hashes, suspicious process command lines, outbound network connections to malicious domains or IPs, and email communications from identified adversary-controlled accounts.
avatar
Arnold Chan@slaz
avatar
SlimKQL
8 days ago
909
Detects the GOST tunnel binary deployed as svchost.exe from a staging directory, identified by its known hash, or by an unsigned PE importing config.dll with a matching MZ header and embedded config.dll reference (reduces FPs from legitimately signed software that imports a DLL of the same name)
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 hours ago
001
Detects the Akira ransomware binary staged as C:\storage\win.exe and identified by its known SHA256 hash
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 hours ago
001
This rule identifies installations of TeamViewer software that are vulnerable to specific CVEs (CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371) by analyzing the 'DeviceTvmSoftwareInventory' dataset. It checks for versioning patterns against known vulnerable build numbers across Windows, Linux, and macOS platforms to pinpoint systems requiring patching.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
408
Page 4 of 1866