Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the presence of GoCaracal, a Go-based Remote Access Trojan (RAT) attributed to the Dark Caracal threat group, based on unique strings and function names indicative of its implant capabilities, including shellcode injection and system discovery.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
002
Detects malicious markdown files (SKILL.md) that impersonate agent instruction files. These files contain hidden-content constructs (like CSS display:none, HTML comments, or invisible Unicode characters) combined with common command execution patterns (like curl, wget, or PowerShell encoded commands), characteristic of infostealer campaigns targeting AI agent platforms.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
002
Detects instances of DLL side-loading where common application helper binaries (ClaudeDesktop.exe or JetBrains) load libcef.dll from untrusted, user-writable directories such as Downloads, Temp, or AppData. This behavior is indicative of the Claude FakeAgent campaign, which leverages side-loading for payload deployment.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
102
This rule detects the termination of critical security software processes (e.g., antivirus agents) by a process that has recently acquired SeDebugPrivilege. This behavior is indicative of a malicious actor attempting to disable endpoint security controls to evade detection.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
005
This rule detects potential tampering with the Huorong security product by monitoring for specific process names (HipsTray.exe, HipsMain.exe, HipsDaemon.exe, wsctrlsvc.exe, TrafficProt.exe) interacting with suspicious API calls or command lines indicative of token privilege manipulation, service blinding, or security product disabling/downgrade.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
205
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
506
Detects the suspicious execution of a file named 'Windowsupdate.exe' located in 'AppData\Local' that is invoked via a command containing 'copy' and '/b'. This behavior is indicative of an attacker attempting to copy or stitch binary files using a masqueraded system process name to evade detection.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
406
Detects the execution of VBS scripts (wscript.exe or cscript.exe) that interact with the Windows Startup folder to create shortcuts. This behavior is associated with persistence mechanisms where malicious scripts create masqueraded shortcuts (e.g., SecurityHealth, OneDriveUpdate) in the user's Startup folder, often using hidden attributes to evade detection.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
2010
This rule monitors for web server exploit attempts (indicated by patterns like JNDI lookups or SQL injection sequences in URI/cookie data) that correlate with a surge in server-side errors (400+ status codes) and subsequent anomalous process creation or outbound network connections from the web server process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
606
This rule monitors web server logs (IIS, W3C, and Azure Application Gateway) for incoming traffic that matches known malicious or automated vulnerability scanners, as well as requests for common system fingerprinting paths (such as /server-status or /.git/config). The rule aggregates these hits by source IP address to identify potential active reconnaissance or vulnerability scanning attempts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
206
This rule monitors for active reconnaissance or scanning behavior by detecting a single source IP interacting with a high number of distinct ports/hosts within a short time frame (NetworkScan) or accessing a high number of distinct URI paths/404 errors (WebContentScan).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
706
Surfaces Silverfort-detected incidents excluding ImpossibleTravel (high FP rate from VPN and mobile users, better covered by XSIAM Analytics UEBA)
avatar
chiki briki@ekkor13
avatar
Detections.ai Community
1 month ago
405
Detects a PowerShell in-memory loader pattern that derives an AES key using Rfc2898DeriveBytes, decrypts an encrypted payload using System.Security.Cryptography.Aes, verifies the content with SHA256, and executes the decrypted code in-memory via [System.Management.Automation.ScriptBlock]::Create. This technique is often used to bypass file-based security controls by executing stage-two payloads directly in memory.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
1 month ago
14012
This rule detects scenarios where the 'MpDefenderCoreService.exe' process or a process attempting to masquerade as it loads 'mpclient.dll' from a directory path outside of the standard Windows Defender installation folders. This behavior is highly indicative of an adversary masquerading as a legitimate Windows Defender service or attempting to hijack a security-related process to evade detection.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
106
Detects the execution of PowerShell with encoded commands, a common technique used by attackers to obfuscate malicious scripts and evade detection.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
7010
Detects suspicious child process creation (e.g., cmd.exe, powershell.exe) originating from Java applications where the command line contains indicators of deserialization vulnerabilities (e.g., FilteredObjectInputStream, Log4jLogEvent). This pattern is often associated with exploitation of Java applications to gain remote code execution.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
1 month ago
1206
Detects instances where Windows Defender Antivirus, real-time protection, or associated security features have been explicitly disabled or modified on Windows endpoints. This is a common indicator of defensive evasion during an attack lifecycle.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
6010
Detects an executable loading an unexpected DLL, indicative of DLL side-loading used to execute a payload while evading static EDR signatures, as observed in CISA's red team engagement.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
306
Detects the execution of PowerShell with obfuscated parameters such as '-WindowStyle Hidden' and '-ExecutionPolicy Bypass' in combination with network-related cmdlets (Invoke-WebRequest) or process manipulation (Start-Process). It also checks for references to common temporary file paths or 'main.exe', often indicative of malicious script execution or payload staging. The rule also includes a filter to identify if the process was initiated by common WSL or Node.js related processes.
avatar
Seb Cantar@sebcantar
avatar
Detections.ai Community
1 month ago
105
Detects when a rule has been added to the Windows Firewall exception list
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
106
Detects the addition of suspicious file names or known potentially unwanted program artifacts to Windows Run registry keys, often used for persistence. The rule correlates registry modifications with potential installer process activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Page 442 of 1870