Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects unauthorized processes attempting to read sensitive browser credential and session data (e.g., 'Login Data', 'Cookies', 'Local State', 'cookies.sqlite', 'logins.json') located in common browser profile paths. This behavior is highly indicative of information-stealing malware attempting to extract saved passwords and session cookies for account hijacking and 2FA/SSO bypass.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
103
Adversaries may create a domain account to maintain access to victim systems.
Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain..
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system.
Office add-ins can be used to add functionality to Office programs
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Detects the use of the "Get-ADComputer" cmdlet in order to identify systems which are configured for unconstrained delegation.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Adversaries may use to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Detects the execution of an MSI file using PowerShell and the WMI Win32_Product class
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Detects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
201
Detects execution and usage of the DSInternals PowerShell module. Which can be used to perform what might be considered as suspicious activity such as dumping DPAPI backup keys or manipulating NTDS.DIT files.
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Detects scriptblock text keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Detects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Detects package installation activities involving potentially compromised TanStack packages during the defined malicious publish window (2026-05-11 to 2026-05-12). The rule monitors common Node.js package managers (npm, pnpm, yarn, bun) and CLI tools for commands attempting to fetch identified affected versions of @tanstack/* libraries.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
103
Detects anomalous outbound network connections from the Grafana MCP (Model Context Protocol) server process to internal private IP address ranges. The rule compares current network activity against a 14-day baseline to filter out known data sources, identifying potentially unauthorized lateral movement or internal network probing via server-side request forgery (SSRF) vulnerabilities.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects anomalous outbound network connections from the Grafana MCP (Model Context Protocol) server process to internal private IP address ranges. The rule compares current network activity against a 14-day baseline to filter out known data sources, identifying potentially unauthorized lateral movement or internal network probing via server-side request forgery (SSRF) vulnerabilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects the SynkLoader RAT by identifying the pythonw.exe process loading a spoofed msvcp150.dll from a specific staging path (\fl\ang\), combined with correlative beaconing activity via repeated network connections to remote endpoints.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
9018
The following analytic detects excessive usage of the nslookup application, which may indicate potential DNS exfiltration attempts. It leverages Sysmon EventCode 1 to monitor process executions, specifically focusing on nslookup.exe. The detection identifies outliers by comparing the frequency of nslookup executions against a calculated threshold. This activity is significant as it can reveal attempts by malware or APT groups to exfiltrate data via DNS queries. If confirmed malicious, this behavior could allow attackers to stealthily transfer sensitive information out of the network, bypassing traditional data exfiltration defenses.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
0010
Detects incoming HTTP requests to a Caddy web server using the TRACE or TRACK methods. These methods are rarely used in legitimate production traffic and are frequently associated with Cross-Site Tracing (XST) attempts, which can be used to bypass security controls and steal sensitive data such as cookies.
avatar
Anmol Vats@jerry
avatar
Detection Engineers
1 month ago
004
Detects requests for files with names suggesting sensitive content (password, secret, apikey, etc.).
avatar
Anmol Vats@jerry
avatar
Detection Engineers
1 month ago
004
Detects computer-account creation (Event ID 4741) by a non-administrative user, indicative of abuse of the default Machine Account Quota to join unauthorized machine accounts for privilege escalation, as exploited by CISA's red team.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
709
Detects creation or modification of the Faronics Deploy 'ScriptRunner.log' file. This artifact records script execution history and download URLs used by the Faronics Deploy management platform, which can be abused by adversaries for persistence or remote command execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
001
Detects creation or modification of the Faronics Deploy 'ScriptRunner.log' file. This artifact records script execution history and download URLs used by the Faronics Deploy management platform, which can be abused by adversaries for persistence or remote command execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
001
Page 438 of 1870