Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the use of 'schtasks.exe' to disable critical Windows Update or ExploitGuard Malware Removal tasks when initiated by 'LockAppHost.exe'. This behavior is highly irregular, as the LockAppHost process is typically associated with the Windows Lock Screen and should not be modifying security-related scheduled tasks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects malicious network connections, file downloads, or process execution associated with the REVSTEALER malware campaign, which utilizes hijacked YouTube channels to distribute fake game-cheat videos that lure users into downloading 'resightloader.exe' from specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
202
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects the use of PowerShell to add Microsoft Defender exclusions (paths or extensions) where the process was initiated by or involves LockAppHost.exe. This behavior is indicative of an attempt to bypass security protections by excluding malicious artifacts from scanning.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
002
Detects the creation of Object Manager symbolic links that redirect the Windows Defender 'WD_SCAN' object to a loopback UNC share path. This behavior is indicative of a symlink exploitation technique (ShieldCrash/CVE-2026-69414) used to manipulate Windows Defender or associated scan operations by redirecting them to an adversary-controlled or loopback-hosted target.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
101
Detects suspicious file activity within directories named 'ShieldCrash' followed by a cloud provider registration or placeholder creation event within a 5-minute window. This behavior is indicative of unauthorized software or an adversary attempting to stage data for exfiltration or create persistent storage aliases outside of legitimate cloud client applications.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
001
Detects suspicious file activity within directories named 'ShieldCrash' followed by a cloud provider registration or placeholder creation event within a 5-minute window. This behavior is indicative of unauthorized software or an adversary attempting to stage data for exfiltration or create persistent storage aliases outside of legitimate cloud client applications.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
001
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
201
Detects high-frequency file creation, modification, or renaming activity involving files with the specific '.df_win' extension, likely indicative of mass encryption activity or automated ransomware behavior. The rule excludes known backup and security software processes to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
001
This rule monitors for outbound network connections to domains and IP addresses associated with known phishing, loader, and C2 infrastructure, including specific ClickFix patterns.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
002
Detects high-frequency TCP/445 connection attempts (a 'connect sweep') characteristic of automated SMB share enumeration, which is commonly used for lateral movement reconnaissance. The rule triggers when a threshold of 40 connection requests occurs from a single source within a 30-second window, specifically targeting SMB-related lateral movement behaviors.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
001
This rule detects potentially malicious activity where multiple critical processes (such as database engines or email clients) are terminated in a short time frame, correlated with a high volume of file creation or modification events on the same device. This behavior is indicative of destructive activity, such as ransomware encrypting data stores or disabling defensive software.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
001
This rule detects potentially malicious activity where multiple critical processes (such as database engines or email clients) are terminated in a short time frame, correlated with a high volume of file creation or modification events on the same device. This behavior is indicative of destructive activity, such as ransomware encrypting data stores or disabling defensive software.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
001
Detects repeated attempts to delete Volume Shadow Copies using WMIC. This is a common technique used by ransomware and other malware to prevent system recovery and inhibit forensic investigations. The rule filters out known backup agents and service accounts and identifies patterns where multiple distinct deletions occur within a 5-minute window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
001
Detects high volumes of file renaming activities involving files with the .df_win extension. This pattern is often indicative of ransomware-like behavior where mass renaming occurs as part of an encryption process, impacting multiple directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
001
Detects Kerberos TGT requests (Event ID 4768) that utilize RC4 (PreAuthType 23) for pre-authentication. This is a common indicator of an Overpass-the-Hash attack, where an adversary uses a stolen NTLM hash to authenticate as a user and request a Kerberos ticket in environments that are typically configured for AES encryption.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
6307
This rule identifies potential command and control (C2) activity by correlating DNS over HTTPS (DoH) requests initiated by non-browser or unsigned processes with subsequent network connections to a known malicious C2 domain (gw.proxyvector.cc) within a 15-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
302
Detects Run key persistence pointing to the known VBScript staging directory (C:\Users\Public\Libraries\Default\Lib\Lib1) used by the worm-like ScreenConnect campaign (Aug 2026), matching known script filenames (WindowsServiceHost.vbs, 1.vbs-4.vbs) invoked via wscript.exe/cscript.exe.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
001
This rule monitors for file and process events involving 'pubspec.yaml' configuration files or specific Flutter-related components such as 'universal_file_viewer' and 'surveyjs_flutter'. This detection logic is designed to track development activities or the inclusion of specific software packages within a Flutter project environment.
avatar
Nate Dunning@nateossprey
avatar
Detections.ai Community
30 days ago
101
Detects instances where common web browsers (msedge, chrome, firefox, iexplore, brave, opera) are initiated with a command line containing a specific suspicious domain 'llove-kitchens.com', indicating potential interaction with a malicious web resource.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
002
Page 401 of 1870