Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Adversaries may communicate using a protocol and port paring that are typically not associated.
For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
205
Detects suspicious PowerShell invocation command parameters
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
305
Remove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
005
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects the presence of known malicious file hashes associated with the Mini Shai-Hulud supply chain compromise (e.g., malicious npm package artifacts). The rule monitors device file, process, and image load events for SHA256 matches.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
103
The following analytic detects instances where an adversary modifies security permissions of a file or directory using commands like "icacls.exe", "cacls.exe", or "xcacls.exe" with deny options.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions.
This activity is significant as it is commonly used by Advanced Persistent Threats (APTs) and coinminer scripts to evade detection and impede access to critical files.
If confirmed malicious, this could allow attackers to maintain persistence and hinder incident response efforts.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
102
Detects JNDI lookup patterns associated with Log4Shell (CVE-2021-44228) exploitation attempts.
avatar
Anmol Vats@jerry
avatar
Detection Engineers
1 month ago
309
Detects the creation, modification, or renaming of PHP files within the 'wp-content/uploads' directory of a WordPress installation. This pattern is commonly indicative of an attacker uploading a web shell to maintain persistence or execute arbitrary code on a compromised web server.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects instances where base64-encoded PHP code, obfuscated behind a 'data:image/gif;base64' MIME type prefix, is written to the disk as a .php file or initiated by web server processes. This pattern is commonly used in file upload bypass attacks to execute arbitrary code.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
102
Detects instances where the process wtass.exe (often associated with specific legacy or third-party enterprise tools) spawns cmd.exe. This pattern is potentially indicative of command-line abuse, where a legitimate application's child process is leveraged to execute shell commands.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects execution of PowerShell.exe initiated by cplsupport.exe with hidden window styles and non-interactive, no-profile flags, which is often indicative of obfuscated command execution or malicious script activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
102
This rule detects unauthorized modification of the desktop wallpaper registry key to an empty string, typically used for desktop defacement or disruptive activity, followed by a system parameter refresh to apply the changes immediately. It monitors for the use of reg.exe to clear the wallpaper registry value and rundll32.exe to invoke the User32.dll UpdatePerUserSystemParameters function, which forces the Windows shell to refresh desktop settings.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
006
Detects the use of VPN clients, tunneling tools (like Tor, ngrok, plink, and SSH port forwarding), and network proxy configurations on endpoints. The rule monitors for known VPN process execution, network connections to VPN provider domains, unauthorized tunnel protocol activity, and Windows registry-based proxy modifications.
avatar
Huse Yin@hsyn
avatar
Detections.ai Community
1 month ago
13040
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects the execution of common command-line utilities and tools used to enumerate virtual machines, hypervisors, and cloud instance information. Adversaries may perform this reconnaissance to identify virtualization environments, sandbox targets, or cloud infrastructure configurations.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
405
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
This rule detects potentially malicious command-line activity involving powershell.exe or mshta.exe that is initiated by a web browser process (chrome.exe, msedge.exe, firefox.exe, or iexplore.exe). It monitors for indicators such as encoded commands, usage of Invoke-Expression, download cradles, hidden window flags, and specific known IOCs, correlating these events with recent browser activity to identify potential drive-by download or browser-based exploitation attempts.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
101
Page 424 of 1870