Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects potential Browser-in-the-Browser (BitB) phishing attacks by identifying suspicious browser pop-up behavior (using window.open flags, hidden address/toolbars) on non-identity-provider domains, followed shortly by credential submission patterns on the same device. This pattern mimics legitimate OAuth or SSO windows to harvest user credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
102
Detects anomalous access to the SharePoint WebPartPages.asmx SOAP endpoint, specifically using the GetWebPartPageConnectionInfo method. This query identifies patterns consistent with the exploitation of CVE-2026-65660, where adversaries attempt to smuggle WebPart template markup (e.g., <%@ Register, XamlServices) after legitimate preview methods have been disabled.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
003
This rule detects potentially malicious POST requests to SharePoint endpoints (such as AddGallery.aspx) that include indicators of WebPartMarkup or ToolPane payloads. This activity attempts to bypass the SPUtility.EnsureAuthentication() check that is typically enforced on the ToolPane.aspx page, potentially allowing unauthorized code execution or configuration manipulation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
103
Detects the execution of binaries that masquerade as legitimate Adobe-signed applications by running from non-standard locations, while simultaneously performing DLL side-loading by loading a malicious 'msvcp140.dll' from the same directory as the executable.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
This rule monitors for various indicators of compromise (IOCs) including malicious domains, IP addresses, specific URI paths, file names, and file hashes. It aggregates telemetry from network, file, process, and certificate events to detect potential threats interacting with known bad infrastructure or executing suspicious files associated with malware campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
001
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
101
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
001
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
101
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
001
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
001
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
001
This rule detects suspicious activity where a user account executes multiple disparate reconnaissance or discovery commands within a 30-minute window. It monitors for the execution of common Windows administration and discovery tools like dsquery, nltest, net, nslookup, and tasklist using specific, non-standard arguments indicative of network or domain reconnaissance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects the use of ntdsutil.exe with arguments indicative of Install From Media (IFM) backup creation, correlated with subsequent access to the ntds.dit file on the same device within a one-hour window. This behavior is commonly associated with attackers attempting to harvest the Active Directory database for offline credential cracking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects the use of ntdsutil.exe to create an Install From Media (IFM) backup of the Active Directory database (NTDS.dit) to a non-standard location, followed closely by the use of 7-Zip (7z.exe or 7za.exe) to archive that specific backup directory, which is a common indicator of credential dumping and exfiltration staging.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
Detects the creation of scheduled tasks, recurring jobs, or webhook subscriptions by a user identity flagged as an AI_AGENT. This activity is monitored for persistence, especially when the event lacks a descriptive context or targets external networks, suggesting potential unauthorized agent behavioral drift or malicious persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects anomalous Kerberos TGS-REQ activity (Event ID 4769) from a single user account targeting five or more distinct Service Principal Names (SPNs) using RC4 encryption (0x17). This pattern is consistent with Kerberoasting techniques used by offensive tools like Rubeus, where service tickets are requested for offline cracking to extract plaintext service account credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects anomalous Kerberos TGT (4768) or TGS (4769) requests where the ticket lifetime exceeds typical domain policy (10 hours), or where the KRBTGT account is explicitly referenced as the target, both of which are high-fidelity indicators of Golden Ticket forgery attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the execution of command-line archiving utilities (e.g., 7z, rar, zip) to create potentially password-protected archives within common staging directories (Temp, Public, ProgramData), followed by an outbound network connection to an external destination. This behavior is consistent with data staging and subsequent exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the creation or modification of WMI Event Subscriptions (Filters, Consumers, and Bindings) using administrative tools like wmic, powershell, or mofcomp. This behavior is commonly used by adversaries to establish persistence or facilitate execution via WMI event triggers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
101
Page 42 of 1870