Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule identifies potential DNS tunneling or beaconing activity by detecting an unusually high volume of DNS queries (exceeding 50 requests) made to a specific domain name within a given timeframe. Such patterns are often associated with C2 communication or data exfiltration via the DNS protocol.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
17049
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
28 days ago
000
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
avatar
Ankit Mehta@Secvyn
Defender - KQL
28 days ago
000
The detection rule identifies network connections to 'dauntingmoon.online' specifically hitting '/api/verification/init' or '/api/verification/check' paths. It validates that both 'session' and 'link_id' query parameters are present in the request. This pattern is indicative of a specific adversary beaconing or command and control (C2) callback mechanism involving session-based authentication or handshake steps with a remote server.
avatar
Ankit Mehta@Secvyn
Defender - KQL
28 days ago
000
Detects network connections initiated by common web browsers to a specific LinodeObjects domain or any subdomains within the linodeobjects.com infrastructure, which may indicate command and control communication or data exfiltration via legitimate cloud storage providers.
avatar
Ankit Mehta@Secvyn
Defender - KQL
28 days ago
000
Detects network connections initiated by common web browsers to a specific LinodeObjects domain or any subdomains within the linodeobjects.com infrastructure, which may indicate command and control communication or data exfiltration via legitimate cloud storage providers.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
28 days ago
000
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
101
This rule detects potential reflective code injection or in-memory loading (fileless) where a DLL or PE image is loaded by mshta.exe or powershell.exe, but the module load event lacks a valid file path on disk (or indicates a device path). This behavior is often associated with the execution of malicious payloads such as the Amatera loader, where payloads are executed directly in memory to evade file-based security detections.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
102
Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
202
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
102
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
101
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
101
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
102
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects instances where OpenVPN service binaries (openvpn.exe or openvpnserv.exe) spawn command-line interpreters (cmd.exe or powershell.exe) with suspicious command-line characters or potentially unbalanced quotes. This behavior may indicate an attempt to leverage OpenVPN for code execution or persistence, often seen in environments where VPN configurations are manipulated to run arbitrary scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
101
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
101
Detects execution of AnyDesk from non-standard directories such as Temp, AppData, or User profile folders, often indicative of unauthorized or portable installation of remote access software.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
202
This rule monitors for three distinct suspicious behaviors on Windows endpoints: the addition of executable files from temporary or user-writable directories to Windows registry run keys for persistence, the creation of repeated hidden log or data files in AppData directories, and unsigned processes accessing browser-related credential storage files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
102
Detects msiexec.exe executing from the Temp directory with suspicious command-line arguments (such as hidden windows) and spawning child processes like cmd.exe, tasklist.exe, or taskkill.exe. This behavior is often indicative of malicious installation scripts attempting to perform discovery or terminate security processes while remaining stealthy.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Page 411 of 1866