Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects evidence of remote service installation and execution, commonly associated with tools like PsExec, PaExec, and RemCom, or the direct use of Windows administrative shares (ADMIN$, C$) to execute binaries remotely. The rule monitors for process creation events involving known service binary names, service creation attempts, or the execution of binaries staged in administrative network shares.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects indicators of Cobalt Strike activity, including the creation of default named pipes, process injection into common LOLBins without legitimate parent processes, and network communication patterns consistent with Cobalt Strike malleable C2 profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) using either the built-in 'comsvcs.dll' library via 'rundll32.exe' or by requesting specific sensitive process access rights to 'lsass.exe' from unauthorized processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects attempts to steal the Active Directory database (ntds.dit) and associated security files by creating volume shadow copies using native Windows utilities like ntdsutil, vssadmin, or wmic. It also monitors for direct file system access or creation attempts related to these sensitive database files within shadow copy paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects anomalous Kerberos Ticket Granting Service (TGS) requests from a single user account and IP within a 10-minute window. It specifically flags accounts requesting a high volume of TGS tickets or accessing multiple distinct services, where the tickets use RC4 encryption (0x17), which is a characteristic of Kerberoasting attacks targeting service accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects anomalous lateral movement behavior where a single user account authenticates via NTLM (LogonType 3, network logon) to three or more distinct hosts within a 30-minute window, without a preceding interactive logon (LogonType 2). This pattern is a strong indicator of an adversary using captured NTLM hashes to move laterally across a Windows environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the abuse of native Windows binaries Regsvr32.exe and Rundll32.exe to execute code from remote sources. Regsvr32 is monitored for 'Squiblydoo'-style execution where scrobj.dll is used to execute remote scriptlets via a URL. Rundll32 is monitored for loading DLLs from remote UNC/WebDAV paths or HTTP URLs, which is a common pattern for proxying malicious code execution to bypass local security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule detects potentially malicious behavior in package manager post-install scripts (npm, pip). It monitors for child processes like shells, network utilities (curl, wget), or command-line arguments indicative of credential harvesting (e.g., accessing .ssh, .aws/credentials, environment variables) initiated by package management processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects the physical connection of unauthorized IP-KVM devices (e.g., PiKVM) to corporate endpoints, which could be used for remote control via HDMI capture and USB HID emulation. This detection monitors Plug and Play (PnP) events for specific device descriptors and hardware identifiers commonly associated with remote access hardware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
203
Detects suspicious outbound HTTPS POST traffic to major generative AI API endpoints (OpenAI, Anthropic, Google) originating from scripting hosts like powershell.exe or python.exe. The detection is triggered by either unusually large outbound payload sizes or the use of unauthorized scripting tools, which is indicative of data exfiltration using AI infrastructure as a relay.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
003
Detects suspicious PowerShell command execution patterns commonly associated with malicious activities, including base64-encoded commands, download cradles used to fetch external content, and various obfuscation techniques like character concatenation or backtick escaping to hide malicious intent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the creation of a remote service (Event ID 7045 or 4697) on a Windows host shortly after a remote SMB logon. The detection specifically looks for service binary paths associated with well-known lateral movement tools like PsExec (PSEXESVC), the ADMIN$ network share, or randomized executable names within the Windows Temp directory, which are common artifacts left by tools such as Impacket psexec.py and CrackMapExec.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects suspicious NTLM network logon events (Logon Type 3) involving privileged accounts that do not have corresponding Kerberos authentication events (4768/4769) in the preceding hour. The detection specifically triggers when a single account logs into two or more distinct hosts within a 15-minute window, which is indicative of lateral movement using compromised credentials or Pass-the-Hash techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule detects potentially malicious PowerShell activity by identifying common obfuscation patterns, including encoded commands (Base64), IEX (Invoke-Expression) download cradles, and execution with hidden windows. It triggers when multiple suspicious flags are present or when an unusually long encoded blob is identified in script blocks, command lines, or process arguments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule detects the use of forged Kerberos Ticket-Granting Tickets (Golden Tickets), which are typically generated by abusing the KRBTGT account's NTLM hash. The rule monitors Windows Event IDs 4768 and 4769 for anomalies including excessively long ticket lifetimes (common in Mimikatz outputs), evidence of tickets used post-KRBTGT reset, or tickets issued for accounts that do not exist in the environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects network beaconing behavior consistent with Cobalt Strike's default malleable C2 profiles. It monitors HTTP GET and POST requests for specific URI patterns commonly used by default Cobalt Strike configurations and triggers when multiple such requests are observed from a single host over a 15-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects potential process injection or process hollowing attempts by correlating Sysmon Event ID 10 (ProcessAccess) events indicating process memory modification permissions (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) with subsequent Sysmon Event ID 8 (CreateRemoteThread) events targeting the same process. This behavior is indicative of an adversary injecting malicious code into a legitimate host process (e.g., svchost.exe, explorer.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
103
Detects the use of legitimate Windows administrative tools (vssadmin, wmic, wbadmin, bcdedit, sc, net) to delete volume shadow copies, clear backup catalogs, disable boot recovery options, or stop critical backup and system services. This behavior is highly characteristic of ransomware activity aiming to prevent data restoration and system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
003
Detects instances where common scripting engines like Python or Node.js are used to spawn command shells (CMD, PowerShell, or Bash) followed by the execution of suspicious commands commonly associated with reconnaissance, file exfiltration, or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
103
Detects potential exploitation of Active Directory Certificate Services (AD CS) misconfigurations (specifically ESC1, involving client-auth EKU and enrollee-supplies-subject). The rule correlates certificate issuance events (4886, 4887, 4888) involving sensitive templates or suspicious subject alternative name (SAN) mismatches with subsequent Kerberos PKINIT authentication (4768) events using the issued certificate.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
103
Detects the clearing of Windows Event Logs via wevtutil, PowerShell, or registry modification, occurring within one hour of a remote interactive or network logon event on the same host. This pattern is indicative of anti-forensic activity often performed following lateral movement or prior to destructive actions like ransomware deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
103
Page 40 of 1870