Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the loading of the ProRAM implant DLL (somkernl.dll) when initiated by known sideloading carriers such as 360speedld.exe or SoftupNotify.exe, which are signed utilities frequently abused for this purpose.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detection of sc.exe utility adding a new service with special permission which hides that service.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
002
Detects command line containing reference to the "::$index_allocation" stream, which can be used as a technique to prevent access to folders or files from tooling such as "explorer.exe" or "powershell.exe"
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
002
This rule detects when PowerShell is used to create or modify a LNK file within the Windows Startup folder. Adversaries often place malicious LNK files in this directory to achieve persistence, ensuring their code executes upon user login.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
608
Detects a pattern of multiple failed authentication attempts (brute force) from an external IP address followed by a successful authentication event on remote access services such as RDP, VPN, or NTLM. The rule filters for non-private IP addresses and flags successes occurring outside of standard business hours.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
508
Detects network requests to unpkg.com or npmmirror for 'index.html' files directly under a package path. This behavior deviates from standard package management usage (which typically fetches tarballs or specific JavaScript modules) and is often associated with adversaries using npm packages as hosting infrastructure for phishing landing pages.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects HTML content that mimics Cloudflare CAPTCHA challenges to perform social engineering (ClickFix). The rule specifically identifies the combination of fake CAPTCHA UI text, connection to suspicious domains (DDR patterns), and JavaScript snippets used to fetch and execute secondary payloads or redirects.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects HTML content containing common indicators of fake Cloudflare 'Verify you are human' CAPTCHA lure pages associated with the Beamglea/ClickFix campaign. These lures often use typosquatted domains or specific API key patterns and include JavaScript code to facilitate the 'copy-and-paste' execution workflow typical of the ClickFix attack technique.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
This rule detects network connections or DNS queries to known phishing domains (typosquatted Microsoft login domains), DeadDrop Resolver domains, and suspicious HTML payloads served from common CDN/package hosting sites (e.g., unpkg.com, npmmirror.com, cdn.jsdelivr.net, yarnpkg.com). These patterns are indicative of initial access attempts via phishing or the secondary stage of malware C2 communication.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the registration of a new scheduled task occurring within a network logon session (LogonType 3). This behavior is characteristic of lateral movement techniques where attackers use remote service execution tools (such as Impacket's atexec or PRTremote) to register and execute tasks on a remote host via SMB/RPC. The rule correlates Windows Security Event 4698 (Task creation) with network logon events and validates the action using Task Scheduler operational logs.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
206
Detects the abuse of the Windows ftp.exe utility to execute a local script file provided via the -s flag. Adversaries may leverage this behavior, often triggered by malicious LNK files, to proxy the execution of commands or scripts.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
006
Detects the use of the native Windows utility 'wbadmin.exe' to initiate a backup procedure targeting the Active Directory database (NTDS.dit) and associated registry hives (SYSTEM, SECURITY). This technique is utilized by adversaries for offline credential harvesting by extracting the directory database file. This behavior has been observed in intrusion campaigns involving ransomware actors like Akira.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
006
Detects new Microsoft Teams chats created by external unmanaged Microsoft accounts, identified by a .cid. prefixed UserId, targeting internal users. It is intended to identify possible impersonation, social engineering, or BEC-style activity.
avatar
Tun Tun Naing@tuntun
avatar
Detections.ai Community
2 months ago
17023
This rule detects potentially malicious activity involving the execution of scripts or the creation of scheduled tasks named 'SysEdgeUpdate'. It monitors for the execution of 'schtasks.exe', 'wscript.exe', or 'cscript.exe' with suspicious command lines related to 'SysEdgeUpdate', and tracks the creation or presence of a 'SysEdgeUpdate.vbs' file within the Microsoft Edge extensions directory, which is a common indicator of persistence mechanisms or malicious extensions.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
1008
Detects instances where 'ebook-edit.exe' (a component of the Calibre software) loads a suspicious DLL ('calibre-launcher.dll') or interacts with 'edit2.hlp' files. This pattern may indicate process hollowing, DLL sideloading, or the execution of malicious payloads masquerading as legitimate Calibre application components.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
108
This rule detects cross-process injection techniques, such as OpenProcess, CreateRemoteThread, and memory modifications, specifically targeting 'svchost.exe' instances that do not appear to be hosting critical Windows services. By filtering out known critical services (e.g., RpcSs, DcomLaunch), the rule flags suspicious attempts to inject code into legitimate service host processes to mask malicious activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
206
This rule detects the creation of a Windows scheduled task named 'TaskHandler' using the schtasks.exe utility. The task is configured to execute a specific file, 'F7u00ex.exe', on system startup under the 'NT AUTHORITY\SYSTEM' account. This behavior is indicative of a persistence mechanism, often associated with the Spark RAT malware, which attempts to maintain a foothold on the system with high-level privileges.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
306
Detects MSBuild process execution originating from command shells loading obfuscated scripts or inline projects associated with PavinLoader.
avatar
Vignesh Keshavan@illusion07
avatar
Detections.ai Community
1 month ago
0012
This rule detects potential reflective code injection or in-memory loading (fileless) where a DLL or PE image is loaded by mshta.exe or powershell.exe, but the module load event lacks a valid file path on disk (or indicates a device path). This behavior is often associated with the execution of malicious payloads such as the Amatera loader, where payloads are executed directly in memory to evade file-based security detections.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Page 439 of 1870