Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
101
Detects anomalous access to specific memory sections associated with Desktop Window Manager (dwm.exe) followed by a crash of the same process within a 30-minute window. This behavioral pattern is often indicative of exploitation attempts targeting DWM memory management to achieve code execution or privilege escalation.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
405
Detects the 'LegacyHive.exe' process initiating child processes running under the SYSTEM account context. This behavior is indicative of potential privilege escalation or malicious persistence mechanisms where a process spawns a child with elevated permissions.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
005
This rule detects instances where a process loads 'offreg.dll' (Offline Registry Library) and concurrently accesses the SAM (Security Account Manager) file. This is a common technique used by attackers to offline-extract local account hashes without using standard registry tools, potentially bypassing basic monitoring of 'reg.exe'.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
205
This rule detects potentially malicious JavaScript files associated with known malicious patterns or suspicious 'preinstall' script behavior within Node.js environments. It monitors for the execution of specific suspicious filenames or the use of common Node.js package management tools (npm, yarn, etc.) in contexts suggesting code generation or build-time abuse.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
204
Detects specific process execution and command-line activity related to NVIDIA GeForce Experience, specifically focusing on scheduled task creation and suspicious file references that may mimic or abuse legitimate update mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
000
Detects anomalous child process creation (e.g., cmd.exe, powershell.exe, rundll32.exe) spawned by the VMware host process 'vmware-vmx.exe'. This behavioral pattern is a high-confidence indicator of potential guest-to-host virtual machine escape, specifically monitoring for activity associated with vulnerabilities like CVE-2026-59346.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
001
Detects the creation or modification of specific dropper/loader files and service worker registration within WordPress directory structures (wp-content/plugins, wp-content/themes, wp-content/uploads). These files are often associated with the injection of malicious scripts (e.g., on-chain resolvers) to facilitate drive-by compromises by site visitors.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
101
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
001
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
201
Detects cortex-xdr-payload.exe connecting to a server outside Palo Alto Networks LRC infrastructure. Attackers can abuse the Live Terminal feature as a pre-installed, EDR-trusted C2 channel by redirecting the payload to their own server using a URL validation bypass in the server hostname check
avatar
chiki briki@ekkor13
avatar
Detections.ai Community
1 month ago
45016
Detects network activity from infrastructure provisioner tools (Terraform, Coder) or shell processes attempting to connect to suspicious domains (e.g., coder-infra.com) that resemble legitimate infrastructure domains. This activity is indicative of credential theft, specifically targeting OIDC tokens, SSH keys, or authentication tokens during automated provisioning processes.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects the execution of Terraform commands (init, apply, plan) that interact with the 'registry.coder.com' domain, or direct network connections to the associated infrastructure. This may indicate the use of unauthorized or compromised Infrastructure-as-Code (IaC) modules or malicious supply chain activity involving Terraform configurations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
This rule identifies endpoints running specific Windows OS versions susceptible to CVE-2026-69414 (ShieldBreak) that currently have Microsoft Defender for Endpoint configured as the active and compliant antivirus solution. This is used for tracking compensating controls across the fleet.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
33053
Detects scripts or files referencing the JSCeal loading chain that invokes node.exe with -r preflight.js to decompress and execute a compiled V8 bytecode app.jsc payload
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects a suspicious sequence of activities where PowerShell downloads or extracts specific zip files (node.zip, build.zip) to staging directories, followed by the execution of associated binaries like node.exe, winpty-agent.exe, or winpty.dll from those same locations. This behavior is indicative of an adversary staging and executing tooling within temporary user directories.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects a hardcoded PEM RSA public key embedded alongside JSCeal-specific compiled V8 bytecode obfuscation artifacts, used to encrypt exfiltrated data or C2 communications
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects Node.js or related helper processes executing shell commands (cmd.exe, powershell.exe) or other processes where the execution involves the 'withCreateProcessUser' argument. This often indicates attempts to bypass execution restrictions or run malicious payloads by utilizing Node.js as an execution proxy within unconventional or temporary directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Page 412 of 1866