Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden windows) initiated by mshta.exe, excluding instances where a .ps1 script file is involved. This pattern often indicates attempts to bypass execution policy or run obfuscated payloads in memory, which is a common behavior of malicious HTA files.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule monitors for scenarios where multiple common GUI applications (such as browsers, explorer, or notepad) are executed in rapid succession (within 2 minutes) from suspicious directories commonly associated with malware staging (e.g., Temp, AppData, or Downloads). This pattern is often indicative of an adversary executing a malicious payload, such as a multi-stage dropper or a file-based installer masquerading as legitimate software.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
Detects suspicious processes executing from user-writable directories (Temp, AppData, Downloads) that are either unsigned or command-line focused on media capture (camera/microphone), while also loading media-related DLLs. The rule correlates this activity with potential spawned hidden UI processes (explorer/notepad) and AnyDesk remote access connectivity, which is a behavioral pattern indicative of remote monitoring or data exfiltration malware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
Detects suspicious processes executing from user-writable directories (Temp, AppData, Downloads) that are either unsigned or command-line focused on media capture (camera/microphone), while also loading media-related DLLs. The rule correlates this activity with potential spawned hidden UI processes (explorer/notepad) and AnyDesk remote access connectivity, which is a behavioral pattern indicative of remote monitoring or data exfiltration malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
000
Detects the enablement of the Remote Desktop Protocol (RDP) by modifying registry keys or service configurations, specifically when triggered by identified remote access tools or common script interpreters (cmd, powershell, etc.) executing from non-standard user-writable paths such as Temp or AppData. This behavior is indicative of lateral movement preparation.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
7012
This rule detects a multi-stage attack pattern associated with Akira ransomware, including AD enumeration using PowerShell, data staging with WinRAR, S3 exfiltration via s5cmd, AnyDesk service installation, registry manipulation for persistence via Safe Mode, and boot configuration changes to facilitate EDR bypass. It also incorporates detection for specific IOCs like attacker jump host RDP connections and malicious file hashes.
avatar
Aamir Muhammad@Aamir
avatar
Detections.ai Community
2 months ago
30074
Detects the execution of known GoCaracal malware samples, identified by specific file hashes or staging file paths, occurring in conjunction with low-level keyboard hook installations using SetWindowsHookEx. This behavior is indicative of active keylogging activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
107
Detects the use of the sc.exe utility to disable critical system, security, and database services, a technique commonly associated with Everest ransomware to prevent service restart during encryption activities.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
2 months ago
15015
Detects instances of PowerShell being launched directly by explorer.exe with command-line arguments indicative of malicious activity, specifically the 'ClickFix' pattern where users are social-engineered to copy/paste malicious commands into the Windows Run dialog.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
26046
Detects suspicious execution of 'browsercore.exe' using common command-line interpreters (cmd.exe, powershell.exe, pwsh.exe). This pattern monitors for specific command-line arguments involving file redirection, content retrieval, or process spawning, which are often indicative of malicious activity or attempts to bypass security controls by leveraging legitimate-looking browser-related binaries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
105
Detects instances where a Windows Scheduled Task is created (Event ID 4698) and subsequently deleted (Event ID 4699) within a very short timeframe (less than 120 seconds). This behavior is often indicative of an adversary creating a temporary task for execution and immediately cleaning up evidence to avoid detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
205
This rule detects scenarios where Microsoft Word (WINWORD.EXE) or Excel (EXCEL.EXE) launch suspicious child processes (e.g., ebook-edit.exe, FineReader.exe) and simultaneously load specific DLL files within a 60-second window. This behavior is indicative of potential document-based exploitation or malware staging where an Office application is used as a dropper or execution vector.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
307
This rule detects instances where a Python interpreter loads the 'snap7.dll' library or executes processes containing 'snap7' or 'python-snap7' in the command line. Snap7 is an open-source library used for communication with Siemens S7 PLCs. This detection helps identify potential unauthorized or suspicious interaction with Industrial Control Systems (ICS) via Python scripts.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
405
Detects when bcdedit or bootcfg is executed and Safeboot registry keys modified within a specified time window
avatar
Sam Harrison@sect0rcybersec
avatar
Detections.ai Community
2 months ago
25032
Detects persistence and configuration activity associated with the CornFlake RAT, including the creation of malicious Windows services (e.g., 'svchost32', 'Cloud Sync Service'), registry run key modifications, and the presence of specific file artifacts like 'sync.dat' and malicious executables within AppData directories.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
2013
Detects the installation of RustDesk or Cloudflared as a persistent Windows service, initiated by a PowerShell script. This behavior is indicative of unauthorized use of remote access or tunneling tools, often observed in intrusion activity such as Bumblebee, AdaptixC2, or Akira ransomware to facilitate persistence and establish reverse tunnels through firewalls.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
105
Detects the creation of a new domain user followed by its addition to sensitive, high-privileged groups (e.g., Domain Admins, Enterprise Admins) using the native Windows net.exe or net1.exe utilities. This pattern aligns with known post-compromise activity observed in campaigns like Bumblebee, AdaptixC2, and Akira ransomware, where attackers create stealthy, elevated accounts (e.g., masquerading as backup service accounts) to maintain persistence and full domain control.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
205
Detects DNS queries using IPv6 (AAAA) records that contain high-entropy, long subdomain strings, which are indicative of DNS tunneling techniques. The rule specifically targets patterns similar to the HOLLOWGRAPH malware, which encodes data within subdomain labels to facilitate C2 communication.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
14013
Page 440 of 1870