Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects network connections or DNS queries to known phishing domains (typosquatted Microsoft login domains), DeadDrop Resolver domains, and suspicious HTML payloads served from common CDN/package hosting sites (e.g., unpkg.com, npmmirror.com, cdn.jsdelivr.net, yarnpkg.com). These patterns are indicative of initial access attempts via phishing or the secondary stage of malware C2 communication.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
101
Detects modifications to the Windows Registry that disable Microsoft Defender Tamper Protection. Tamper Protection is a security feature that prevents malicious changes to security settings, including the disabling of antivirus and real-time monitoring.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects attempts to tamper with Microsoft Windows Defender configuration, specifically by modifying exclusion paths via PowerShell cmdlets (Add-MpPreference, Set-MpPreference), direct registry modifications, or forced Group Policy updates. It also monitors for the disabling of Tamper Protection via registry and the creation of scheduled tasks designed to apply Defender exclusions.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects attempts to tamper with Microsoft Windows Defender configuration, specifically by modifying exclusion paths via PowerShell cmdlets (Add-MpPreference, Set-MpPreference), direct registry modifications, or forced Group Policy updates. It also monitors for the disabling of Tamper Protection via registry and the creation of scheduled tasks designed to apply Defender exclusions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects modifications to the Windows Registry that disable Microsoft Defender Tamper Protection. Tamper Protection is a security feature that prevents malicious changes to security settings, including the disabling of antivirus and real-time monitoring.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects unusual executables that are not recognized web browsers initiating direct network connections to Google DNS-over-HTTPS (DoH) services. This behavior is often associated with malware attempting to bypass local DNS resolution to communicate with command-and-control servers covertly.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
9013
Detects network connections to known suspicious infrastructure, including specific domains associated with Session, catbox.moe, or targeted npm registry and GitHub API queries initiated by common command-line utilities. This behavior often suggests adversary communication, data staging, or potential tool/malware delivery.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
406
Detects behavioral indicators consistent with local privilege escalation targeting Windows ALPC subsystem vulnerabilities (CVE-2026-85880). The rule correlates: 1) Unsigned or low-prevalence processes loading sensitive ALPC-related DLLs (rpcss.dll, ntdll.dll), 2) Subsequent crashes or restarts of critical ALPC-handling system components (lsass.exe, RPCSS, wuauserv), and 3) The generation of a new SYSTEM-level process by a parent that was not previously running as SYSTEM within a short temporal window.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
30 days ago
100
This rule detects the installation of browser extensions that occur during an idle user session (greater than 7 minutes). This behavior is consistent with automated, remote-driven synthetic input injection, often utilized by malware (e.g., NinjaMare) to install malicious extensions without user consent while the system is unattended.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
102
This rule detects a suspicious sequence of events where a process with a name resembling an updater (AutoUpdate.exe or au.exe) accesses a specific remote configuration file from a herokuapp.com URL, followed by the creation or modification of specific application binaries (e.g., InstaTime.exe, ffmpegsumo.dll). This pattern is indicative of a supply chain compromise or an automated software update hijacking where malicious binaries are staged to replace legitimate application components.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
102
Detects a single device requesting Entra ID access/refresh tokens on behalf of multiple distinct users in a short window, indicative of Primary Refresh Token (PRT) theft used to impersonate other users, as CISA's red team did against an application owner.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
5015
Detects non-administrative access querying SCCM to enumerate user-device relationships, used by CISA's red team to identify which workstations belonged to high-value targets.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
8015
Detects command-line execution (cmd.exe, powershell.exe) originating from a python.exe process tree, correlated with long-running, frequent outbound public network connections from the same python.exe process. This behavior is consistent with the SynkLoader RAT module, where a loader uses a Python process to execute system commands and maintain persistent C2 channels.
Anitha A@aanitha
avatar
Detections.ai Community
1 month ago
14027
This rule performs a comprehensive hunt for activities associated with the MuddyWater (also known as Boggy Serpens) threat group, specifically relating to their 'Operation Olalampo' campaign. It monitors for spearphishing artifacts (lure documents and attachments), execution of specific malware and drop artifacts, the use of LOLBins by Office applications, unauthorized remote access via AnyDesk, Telegram-based C2 communication, and persistence mechanisms such as registry run keys and specific file extensions (.wdlp).
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
290141
Detects access to the AWS CLI credentials file (~/.aws/credentials) in a user's home directory, used by CISA's red team to harvest long-lived static IAM access keys.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
5014
This rule detects unauthorized modifications to sensitive Windows registry keys related to SCHANNEL ciphers, protocols, or FIPS algorithm policies. It specifically identifies when these security settings are weakened (e.g., enabling insecure algorithms or disabling security defaults) by interactive users rather than authorized system processes or configuration management tools like Intune or SCCM.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Detects unauthorized modifications to critical authentication-related configuration files and registry keys. Specifically monitors changes to LSA security packages and notification packages on Windows systems, as well as PAM configuration file modifications on Linux systems, when performed by unsigned or untrusted processes outside of known installer activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects unauthorized modifications to critical authentication-related configuration files and registry keys. Specifically monitors changes to LSA security packages and notification packages on Windows systems, as well as PAM configuration file modifications on Linux systems, when performed by unsigned or untrusted processes outside of known installer activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects unauthorized modifications to critical authentication-related configuration files and registry keys. Specifically monitors changes to LSA security packages and notification packages on Windows systems, as well as PAM configuration file modifications on Linux systems, when performed by unsigned or untrusted processes outside of known installer activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Page 425 of 1870