Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
000
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
Detects authentication to a web application using default/built-in account credentials followed by outbound mail sent from an internal address — the technique CISA's red team used to send phishing email from a trusted internal identity.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
6011
Detects access to files containing cleartext credentials on an administrative workstation, followed by their use to authenticate to a sensitive business system — the initial-access path CISA's red team used against SBS 1.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
33011
Shows all Kerberos authentication activity on domain controllers - TGT requests, TGS requests, and pre-auth failures (4768/4769/4771). Good for hunting credential attacks, AS-REP roasting, weak encryption usage, and account lockout troubleshooting.
avatar
chiki briki@ekkor13
avatar
Detections.ai Community
2 months ago
35053
Detects the use of PowerShell (Invoke-WebRequest or Invoke-RestMethod) to download files to the AppData directory, followed by the execution of a file using a 'token-raw' argument. This pattern is often associated with malicious payload delivery and execution.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
11021
Detects the execution of known Remote Monitoring and Management (RMM) and remote access tools. The rule specifically flags these tools when they are executed from high-risk directories such as AppData, Temp, Downloads, or ProgramData, which is a common indicator of unauthorized installation or persistence efforts by an adversary.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
10021
The following analytic detects the execution of JScript using the cscript.exe process.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry.
This behavior is significant because JScript files are typically executed by wscript.exe, making cscript.exe execution unusual and potentially indicative of malicious activity, such as the FIN7 group's tactics.
If confirmed malicious, this activity could allow attackers to execute arbitrary scripts, leading to code execution, data exfiltration, or further system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
001
Detects attempts to stop or reconfigure critical Windows security services (such as WinDefend, WscSvc, Sense, and WdNisSvc) using the Service Control Manager (sc.exe) or by modifying service registry keys via reg.exe. This behavior is indicative of an adversary attempting to disable EDR/AV solutions to evade detection.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
000
This rule detects the use of raw sockets by 'ERAAgent.exe' by monitoring for socket I/O control (Ioctl) operations involving 'SIO_RCVALL'. This configuration, often associated with promiscuous mode, allows an application to capture all network traffic received by the network interface, a behavior commonly used by network sniffing tools or malicious implants to intercept sensitive data.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Detects behavior where the ERAAgent process writes a file to disk and executes that same file shortly after (within 5 minutes). This pattern is consistent with staged payload delivery, decompression, or assembly often observed in malicious activity, specifically referencing SLEEPWALKER malware patterns.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
Page 430 of 1870