Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the modification of the Print Spooler (Spooler) Windows service configuration via command-line registry utilities (reg.exe or regedit.exe). This activity may indicate an attempt to restore or re-enable the Print Spooler service, which is frequently targeted for disabling as a mitigation strategy against vulnerabilities like PrintNightmare.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
004
Detects potential anti-forensic activities performed by malware, specifically the use of 'attrib.exe' to hide files and 'cmd.exe' with 'del /f /q' to forcibly remove dropped payloads. These actions are common indicators of a cleanup phase in a malware lifecycle to hinder analysis.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
004
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
000
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
Detects instances where OpenVPN service binaries (openvpn.exe or openvpnserv.exe) spawn command-line interpreters (cmd.exe or powershell.exe) with suspicious command-line characters or potentially unbalanced quotes. This behavior may indicate an attempt to leverage OpenVPN for code execution or persistence, often seen in environments where VPN configurations are manipulated to run arbitrary scripts.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
Detects instances where OpenVPN service binaries (openvpn.exe or openvpnserv.exe) spawn command-line interpreters (cmd.exe or powershell.exe) with suspicious command-line characters or potentially unbalanced quotes. This behavior may indicate an attempt to leverage OpenVPN for code execution or persistence, often seen in environments where VPN configurations are manipulated to run arbitrary scripts.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
000
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
Detects instances where OpenVPN service binaries (openvpn.exe or openvpnserv.exe) spawn command-line interpreters (cmd.exe or powershell.exe) with suspicious command-line characters or potentially unbalanced quotes. This behavior may indicate an attempt to leverage OpenVPN for code execution or persistence, often seen in environments where VPN configurations are manipulated to run arbitrary scripts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
This rule detects potential malicious activity where a process attempts to communicate over DNS over HTTPS (DoH) using common public resolvers (e.g., Google DNS) while simultaneously establishing persistence via Windows Registry 'Run' keys. It excludes common, legitimate applications known to use DoH, focusing on unexpected processes. The detection relies on correlating network events (DoH to known public resolvers) with registry modification events occurring within a 30-minute window of the network activity.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
709
Detects installation of a Windows service (Security EventID 4697)
named after known VirtualBox Guest Additions components (VBoxGuest, VBoxMouse, VBoxSF,
VBoxService, VBoxVideo, VBoxWDDM). Fires when either:
(a) the service binary is registered outside the legitimate VirtualBox install/driver
paths, or
(b) a driver-class component name (VBoxGuest/VBoxMouse/VBoxSF/VBoxVideo/VBoxWDDM) is
registered as a user-mode/own-process service instead of a kernel or file-system
driver — a structural mismatch that cannot occur with the genuine component and is
a strong indicator of name-based masquerading (T1036.005).
Adversaries reuse trusted VirtualBox names to blend malicious persistence into expected
guest-VM/EDR-noise telemetry.
avatar
Pavan Pothamsetti@pepete
avatar
Detections.ai Community
2 months ago
4130
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
Detects suspicious activity associated with the exploitation of a vulnerability in N-central (CVE-2026-86218). The rule monitors for unauthorized child process spawning by N-central components, creation of files in the application directory consistent with web shells, outbound network connections indicative of command and control, and the creation of new local or service accounts for persistence.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
This rule identifies potential command and control (C2) activity by correlating DNS over HTTPS (DoH) requests initiated by non-browser or unsigned processes with subsequent network connections to a known malicious C2 domain (gw.proxyvector.cc) within a 15-minute window.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
000
Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
Detects the creation or modification of specific dropper/loader files and service worker registration within WordPress directory structures (wp-content/plugins, wp-content/themes, wp-content/uploads). These files are often associated with the injection of malicious scripts (e.g., on-chain resolvers) to facilitate drive-by compromises by site visitors.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
This rule identifies potential command and control (C2) activity by correlating DNS over HTTPS (DoH) requests initiated by non-browser or unsigned processes with subsequent network connections to a known malicious C2 domain (gw.proxyvector.cc) within a 15-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
000
Detects suspicious activity associated with the exploitation of a vulnerability in N-central (CVE-2026-86218). The rule monitors for unauthorized child process spawning by N-central components, creation of files in the application directory consistent with web shells, outbound network connections indicative of command and control, and the creation of new local or service accounts for persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
000
Page 433 of 1870