Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution or presence of files, processes, or paths associated with the 'SnowKiller' malware or tool, as identified by keyword matching in process event logs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
005
This rule detects modifications to the security descriptors (ACLs) of sensitive Active Directory objects, specifically targeting additions of powerful rights like GenericAll, GenericWrite, WriteDacl, or ForceChangePassword. Monitoring these changes on privileged objects such as Domain Admins, Enterprise Admins, and Domain Controllers is critical for detecting potential privilege escalation or persistence efforts.
avatar
Ankit Mehta@Secvyn
Defender - KQL
27 days ago
000
Detects Active Directory Certificate Services (AD CS) certificate requests that utilize NTLM authentication rather than Kerberos. This behavior is indicative of potential NTLM relay attacks (ESC8), where an attacker forces a machine account to authenticate to the AD CS web enrollment endpoint via NTLM to obtain a certificate on behalf of that machine.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
1809
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
103
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
103
This rule detects the execution of potentially malicious files (executables, scripts) from user-writable directories (Downloads, AppData, Desktop) where the file appears to be related to a ZIP archive recently downloaded or extracted by an archive handler or browser. It correlates process execution events with file creation events from ZIP archives to identify potential user-execution of malicious payloads delivered via ZIP files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
103
Detects execution of AnyDesk from non-standard directories such as Temp, AppData, or User profile folders, often indicative of unauthorized or portable installation of remote access software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
203
This rule monitors for three distinct suspicious behaviors on Windows endpoints: the addition of executable files from temporary or user-writable directories to Windows registry run keys for persistence, the creation of repeated hidden log or data files in AppData directories, and unsigned processes accessing browser-related credential storage files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
103
This rule monitors DeviceNetworkEvents for outbound connections to a list of known malicious or suspicious IP addresses. This activity is indicative of potential command and control (C2) communication or unauthorized data exfiltration.
avatar
Ankit Mehta@Secvyn
Defender - KQL
27 days ago
000
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
1 month ago
101
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
201
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
101
The following analytic identifies public network connections initiated by Living Off the Land Binaries and Scripts (LOLBAS) that rarely require direct outbound network access.
It leverages the Network Traffic data model and focuses on native Windows binaries where any public destination should be investigated and explicitly approved.
This activity may indicate proxy execution, process injection, payload download, command-and-control, or other abuse of trusted binaries to evade security controls.
Keep in mind that some of these binaries, such as Netsh.exe, Gpscript.exe, Wmic.exe, etc., will occasionally communicate with public network resources to perform their intended function.
Exclude said processes from the detection if they are too noisy for your environment.
Join this detection with the Process Execution events to provide context and avoid false positives.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
204
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
000
Detects known malicious file hashes for GRAYRABBIT delivery chain components: trojanized 7zp.dll loader, encrypted PE loader shellcode, and GRAYRABBIT backdoor core.dll, gated on PE structural validity and filesize
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects known malicious file hashes for GRAYRABBIT delivery chain components: trojanized 7zp.dll loader, encrypted PE loader shellcode, and GRAYRABBIT backdoor core.dll, gated on PE structural validity and filesize
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Detects trojanized 7z.dll loader and encrypted GRAYRABBIT payload components dropped during the UNC3569 exploit chain
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects trojanized 7z.dll loader and encrypted GRAYRABBIT payload components dropped during the UNC3569 exploit chain
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
Detects trojanized 7z.dll loader and encrypted GRAYRABBIT payload components dropped during the UNC3569 exploit chain
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Page 404 of 1870