Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects unauthorized processes accessing sensitive web browser files (login data, cookies, local state) from suspicious or non-standard paths. This is a common behavioral pattern for infostealers attempting to exfiltrate user credentials and browser session tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
202
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
This rule monitors for active reconnaissance or scanning behavior by detecting a single source IP interacting with a high number of distinct ports/hosts within a short time frame (NetworkScan) or accessing a high number of distinct URI paths/404 errors (WebContentScan).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
102
This rule monitors web server logs (IIS, W3C, and Azure Application Gateway) for incoming traffic that matches known malicious or automated vulnerability scanners, as well as requests for common system fingerprinting paths (such as /server-status or /.git/config). The rule aggregates these hits by source IP address to identify potential active reconnaissance or vulnerability scanning attempts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
This rule monitors for web server exploit attempts (indicated by patterns like JNDI lookups or SQL injection sequences in URI/cookie data) that correlate with a surge in server-side errors (400+ status codes) and subsequent anomalous process creation or outbound network connections from the web server process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects the execution or presence of files, processes, or paths associated with the 'SnowKiller' malware or tool, as identified by keyword matching in process event logs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
202
Detects a specific evasion behavior associated with the NinjaMare malware, where a process idles for at least 7 minutes before moving its window to off-screen coordinates during automated mouse or keystroke input, followed by restoring the window to its original position.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
102
Detects Evil-WinRM / WinRM-fs usage or wsmprovhost.exe-spawned PowerShell tied specifically to bird-agent backdoor artifacts (cplsupport, wtass, config.toml) or encoded/download-cradle command patterns, rather than any WinRM session, reducing noise from routine remote administration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects instances where the process wtass.exe (often associated with specific legacy or third-party enterprise tools) spawns cmd.exe. This pattern is potentially indicative of command-line abuse, where a legitimate application's child process is leveraged to execute shell commands.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects the modification or creation of the 'SealedConfig' value within the 'Software\synapse\Config' registry key, correlated with the deletion of a 'config.toml' file on the same device. This pattern may indicate an adversary tampering with Synapse software configuration or attempting to remove audit/configuration trails.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
This rule detects modifications to Windows Registry persistence keys (Run and RunOnce) associated with specific suspicious filenames ('cplsupport.exe', 'wtass.exe'), as well as modifications to specific Synapse agent configuration registry keys. These patterns are often associated with persistence mechanisms or unauthorized software configuration changes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
102
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects the execution of an executable file located within the Windows Temp directory structure via the command prompt (cmd.exe). This pattern is commonly associated with the execution of downloaded payloads, droppers, or staged malware that are moved to temporary directories to evade initial detection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Page 400 of 1870