Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value.
The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts.
When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
703
Detects network activity from infrastructure provisioner tools (Terraform, Coder) or shell processes attempting to connect to suspicious domains (e.g., coder-infra.com) that resemble legitimate infrastructure domains. This activity is indicative of credential theft, specifically targeting OIDC tokens, SSH keys, or authentication tokens during automated provisioning processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the execution of Terraform commands (init, apply, plan) that interact with the 'registry.coder.com' domain, or direct network connections to the associated infrastructure. This may indicate the use of unauthorized or compromised Infrastructure-as-Code (IaC) modules or malicious supply chain activity involving Terraform configurations.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects the execution of Terraform commands (init, apply, plan) that interact with the 'registry.coder.com' domain, or direct network connections to the associated infrastructure. This may indicate the use of unauthorized or compromised Infrastructure-as-Code (IaC) modules or malicious supply chain activity involving Terraform configurations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the restoration of files from the defender quarantine
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
103
Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services.
Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start.
Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
103
Detects a child process spawned by 'winrshost.exe', which suggests remote command execution through Windows Remote Shell (WinRs) and may indicate potential lateral movement activity.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
203
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
003
Detects the use of the 'Pubprn.vbs' Microsoft signed script to execute commands.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
403
The following analytic identifies processes running from %temp% directory file paths. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
001
This rule detects DNS requests to common cloud-based infrastructure providers often used by adversaries for Command and Control (C2) operations, including AWS API Gateway, Azure App Service, Google Cloud Functions, and Cloudflare Workers. These domains are frequently leveraged to host redirectors, beaconing infrastructure, or malicious payloads.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
9019
This rule detects the presence of HardBreacher proof-of-concept executables or DLLs containing the string 'SolidSnake.dll'. This identifier is associated with the payload delivery mechanism for a Kaspersky Endpoint Security exploit.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
003
Detects execution of pythonw.exe (windowless Python) from user-writable directories (e.g., AppData, Temp, Downloads) when launched by common parent processes typically associated with initial access or execution, indicative of the SynkLoader C2 malware.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
2024
Page 434 of 1870