Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects instances where a non-SYSTEM process attempts to open a handle to winlogon.exe. Since winlogon.exe typically runs as SYSTEM and manages user sessions, unauthorized access to its process handle is often a precursor to credential dumping or token manipulation attacks aimed at escalating privileges to SYSTEM.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
8011
Detects the registration of a new scheduled task occurring within a network logon session (LogonType 3). This behavior is characteristic of lateral movement techniques where attackers use remote service execution tools (such as Impacket's atexec or PRTremote) to register and execute tasks on a remote host via SMB/RPC. The rule correlates Windows Security Event 4698 (Task creation) with network logon events and validates the action using Task Scheduler operational logs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
5010
Detects instances where Microsoft Outlook (OUTLOOK.EXE) initiates common living-off-the-land (LotL) binaries that are often abused by malicious attachments or macros to execute secondary commands, such as PowerShell, command prompt, or script host engines.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
11016
Detects execution of PowerShell commands that use obfuscated [char[]] hex arrays in conjunction with 'iex' (Invoke-Expression) to run code in memory. This pattern is commonly used by loaders like SynkLoader (cleaner.ps1) to execute scripts while avoiding disk artifacts.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
23030
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects Python processes executing common system and network enumeration tools (e.g., net.exe, tasklist.exe, dsquery, Get-ADUser). This activity is indicative of the SynkLoader system profiler module, used to size the victim environment for ransom-value estimation and lateral movement preparation.
Anitha A@aanitha
avatar
Detections.ai Community
1 month ago
504
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
101
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
000
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
Page 429 of 1870