Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects the creation, modification, or renaming of unsigned executable files (.exe, .dll, .sys, .efi) within critical Windows system directories (System32, SysWOW64, drivers, boot). The rule excludes activity triggered by known trusted OS update processes, such as TrustedInstaller or Windows Update services, and optionally flags occurrences outside defined maintenance windows.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects unexpected crashes of major security software agents (e.g., Antivirus, EDR) that are not associated with authorized vendor update or installation activities, potentially indicating tampering or exploitation attempts to disable security controls.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects modifications to Group Policy Objects (GPO) or Microsoft Entra (formerly Azure AD) policies that weaken established security controls. For GPO, it monitors Event ID 5136 for changes to security-relevant attributes (e.g., disabling firewall or real-time monitoring) in Active Directory. For Entra, it monitors audit logs for administrative operations that reduce security posture, such as disabling MFA, lowering authentication trust, or deleting Conditional Access policies. It includes filters to exclude legitimate, documented change management activities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
101
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule monitors for scenarios where multiple common GUI applications (such as browsers, explorer, or notepad) are executed in rapid succession (within 2 minutes) from suspicious directories commonly associated with malware staging (e.g., Temp, AppData, or Downloads). This pattern is often indicative of an adversary executing a malicious payload, such as a multi-stage dropper or a file-based installer masquerading as legitimate software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
001
Detects the creation of new executable files within a directory path containing 'Download'. This behavior is often associated with the delivery of malicious payloads via browser downloads or other file transfer mechanisms, followed by potential user execution.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
6019
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
This rule detects the presence or execution of a file named 'GlobalProtect.exe' within the Palo Alto GlobalProtect directory. It focuses on identifying potentially masqueraded or unauthorized binaries by monitoring file events and associated process execution. This pattern is commonly used by attackers to disguise malicious files as legitimate security software to evade detection.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
100
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
Detects the execution of the Windows FTP client (ftp.exe) initiated by command-line interpreters such as cmd.exe, powershell.exe, or wscript.exe, specifically when utilizing the '-s:' flag. This flag is commonly used to provide a text file containing FTP commands, which is a frequent technique for automated file transfers or exfiltration during post-exploitation activities.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
23015
Page 426 of 1870