Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
000
The following analytic detects .cab files being written to disk.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on events where the file name is '*.cab' and the action is 'write'.
This activity can be significant as .cab files can be used to deliver malicious payloads, including embedded .url files that execute harmful code.
If confirmed malicious, this behavior could lead to unauthorized code execution and potential system compromise.
Analysts should review the file path and associated artifacts for further investigation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
101
Detects the use of the 'netsh wlan show profile' command with the 'key=clear' argument, which is used to display the plaintext passwords of stored WiFi profiles on a Windows system.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
207
This rule identifies devices in the environment that are running software identified as vulnerable to CVE-2026-62890. It aggregates the affected device names along with the associated software names, versions, and vulnerability severity levels.
avatar
Mikio Nakamaru@mikionakamaru
avatar
Detections.ai Community
1 month ago
7026
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects suspicious service installation patterns involving WmiPrvSE, common in lateral movement techniques.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects file creation, modification, or renaming in System32 by TieringEngineService.exe or MsMpEng.exe within a short time frame.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects file creation, modification, or renaming in System32 by TieringEngineService.exe or MsMpEng.exe within a short time frame.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects file creation, modification, or renaming in System32 by TieringEngineService.exe or MsMpEng.exe within a short time frame.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects remote service creation consistent with PsExec-style lateral movement by correlating network logons (Type 3) with subsequent service installations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects NTLM network logons (NtLmSsp) for accounts that may have been targets of certificate-based identity abuse (e.g., ESC1). Attackers often leverage this technique to extract NTLM hashes from PKINIT TGT PACs and subsequently utilize Pass-the-Hash for lateral movement within the network.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
204
Detects suspicious DNS queries to external service interaction domains often used for out-of-band interactions after successful RCE
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
0018
This is something I have seen many times during my years working in cybersecurity: users download software with a filename they recognize and trust, but the file behind that name can be something completely different.

Monitoring the filename is not enough. Monitoring the hash is better, but legitimate software changes constantly: new version, new SHA256, another hash to validate and maintain. So I started thinking about how AI agents could help us here — not by deciding what is malicious, but by doing the repetitive work for us.

For this research, I built an AI-maintained baseline of legitimate software and used it from KQL to hunt two different scenarios:

🎯 Known filename + Unknown hash + Untrusted download source
avatar
Sergio Albea@Sergio_Albea
avatar
01 | 🇨🇭 Swiss Cyber Hunters
1 month ago
14126
Page 420 of 1870