Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Detects file system operations targeting common user directories and specific file extensions (.bak, .backup, .locked) often associated with data exfiltration, staging, or ransomware activity.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
105
Detects the creation of a Windows Scheduled Task (Event ID 4698) that uses the 'InteractiveToken' LogonType, where the user specified to execute the task is different from the user who registered the task. This behavior is indicative of potential session hijacking or lateral movement techniques, such as those used by tools like 'atexec' or to facilitate PRT (Primary Refresh Token) theft.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
3011
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects WinRAR SFX droppers deploying CCProxy proxy server with associated configuration and account files (CCProxy.ini, AccInfo.ini, renamed svchost.exe)
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects WinRAR SFX droppers deploying CCProxy proxy server with associated configuration and account files (CCProxy.ini, AccInfo.ini, renamed svchost.exe)
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Detects WinRAR SFX droppers deploying CCProxy proxy server with associated configuration and account files (CCProxy.ini, AccInfo.ini, renamed svchost.exe)
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects SoftEther VPN bridge dropper/installer disguised as svchost.exe with masquerading MixedRealityOpen service, based on install script and dropped files (a.Bat, hamcore.se2, vpn_server.config)
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
100
Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects files referencing malicious implant install paths under C:\Windows\Fonts\web used to blend with legitimate system files
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects the creation of a Windows service named 'WpnUserHost' or the modification of its registry configuration where the binary path does not reside within the System32 directory. This behavior is indicative of a potential attempt to masquerade a malicious service or achieve persistence using a legitimate-sounding service name.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Detects the creation of a Windows service named 'WpnUserHost' or the modification of its registry configuration where the binary path does not reside within the System32 directory. This behavior is indicative of a potential attempt to masquerade a malicious service or achieve persistence using a legitimate-sounding service name.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects the creation of a Windows service named 'WpnUserHost' or the modification of its registry configuration where the binary path does not reside within the System32 directory. This behavior is indicative of a potential attempt to masquerade a malicious service or achieve persistence using a legitimate-sounding service name.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects PyInstaller-built UltraVNC installer renamed to svchost.exe and staged for deployment to the non-standard C:\Windows\Fonts\web directory
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
The following analytic detects a Python process making an outbound network connection during package installation.
Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.
This activity is significant because it allows adversaries to establish a foothold or exfiltrate data without any direct interaction from the victim beyond running `pip install`.
If confirmed malicious, this could indicate a successful software supply chain compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
0017
TeamViewer_Desktop.exe is create during install
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
102
Enumerates Active Directory to determine computers that are joined to the domain
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
102
Page 427 of 1870