Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
001
Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
001
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
001
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
001
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
001
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
101
Detects instances where the Kaspersky antivirus process (avp.exe) spawns potentially malicious or administrative binaries like cmd.exe, powershell.exe, or specific artifacts related to 'HardBreacher'. This behavior is highly irregular as antivirus software typically does not initiate these types of processes under high-privilege tokens.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
207
Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
101
Detects Python processes executing common system and network enumeration tools (e.g., net.exe, tasklist.exe, dsquery, Get-ADUser). This activity is indicative of the SynkLoader system profiler module, used to size the victim environment for ransom-value estimation and lateral movement preparation.
Anitha A@aanitha
avatar
Federal Signal Detections
1 month ago
208
Detects instances where the NW.js (Node-Webkit) framework binaries (nw.exe, node.exe) spawn common command-line interpreters or script-hosting utilities (e.g., cmd.exe, powershell.exe, wscript.exe) while executing associated application files like main.js or nw.pak. This behavior is indicative of potential exploitation of a browser-based application to gain shell access or execute arbitrary code on the host system.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
303
This rule detects unauthorized modifications to browser search provider settings in the Windows Registry, targeting keys associated with Chrome and Microsoft Edge search configuration. This activity is often indicative of browser hijacking or search engine redirection campaigns, such as the NinjaMare malware.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
1203
Detects Evil-WinRM / WinRM-fs usage or wsmprovhost.exe-spawned PowerShell tied specifically to bird-agent backdoor artifacts (cplsupport, wtass, config.toml) or encoded/download-cradle command patterns, rather than any WinRM session, reducing noise from routine remote administration.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
403
Detects instances where the process wtass.exe (often associated with specific legacy or third-party enterprise tools) spawns cmd.exe. This pattern is potentially indicative of command-line abuse, where a legitimate application's child process is leveraged to execute shell commands.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Detects instances where the Windows Remote Management host process (wsmprovhost.exe) is associated with the execution of specific suspicious files (config.toml, cplsupport.exe, or wtass.exe) within a short time window. This activity often indicates post-exploitation behavior or remote execution of secondary tools using WinRM.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Detects modifications to the 'metrics_interval' registry value within the 'Software\SynapseAgent' key. This activity suggests configuration changes to the SynapseAgent, which could indicate tampering with agent telemetry or polling frequency.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
This rule detects modifications to Windows Registry persistence keys (Run and RunOnce) associated with specific suspicious filenames ('cplsupport.exe', 'wtass.exe'), as well as modifications to specific Synapse agent configuration registry keys. These patterns are often associated with persistence mechanisms or unauthorized software configuration changes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
103
This rule monitors DNS queries and network connection events for interactions with a list of domains associated with the Kali365 infrastructure. It flags activity by identifying both direct matches and subdomains associated with 'ssengineers.com' and 'clientengagenow.de', often used in phishing or C2 communications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
103
Detects instances where base64-encoded PHP code, obfuscated behind a 'data:image/gif;base64' MIME type prefix, is written to the disk as a .php file or initiated by web server processes. This pattern is commonly used in file upload bypass attacks to execute arbitrary code.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Detects the use of the Windows 'diskpart' utility combined with a script or command execution containing 'clean all', which performs a destructive multi-pass overwrite of disk data structures to render it irrecoverable. This behavior is typically associated with malicious data destruction or wiping activities.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
001
Detects the execution of vssadmin.exe to delete volume shadow copies or attempts to clear recovery-related directories such as SoftwareDistribution or Windows.old. This behavior is indicative of ransomware or destructive activity aimed at inhibiting system recovery.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
001
Page 413 of 1870