Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
avatar
Lenny Post@LennyPost
avatar
Detection & Hunting Community
2 months ago
1282189
This rule detects cross-process injection techniques, such as OpenProcess, CreateRemoteThread, and memory modifications, specifically targeting 'svchost.exe' instances that do not appear to be hosting critical Windows services. By filtering out known critical services (e.g., RpcSs, DcomLaunch), the rule flags suspicious attempts to inject code into legitimate service host processes to mask malicious activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
102
This rule detects in-memory patching of critical Windows security functions, specifically AmsiScanBuffer (used by AMSI) and EtwEventWrite (used by ETW). It monitors for suspicious API calls such as VirtualProtect, WriteProcessMemory, NtProtectVirtualMemory, or NtWriteVirtualMemory targeting these specific DLLs (amsi.dll and ntdll.dll), which is a common technique used by malware and offensive security tools to blind endpoint security and logging mechanisms.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
102
This rule detects in-memory patching of critical Windows security functions, specifically AmsiScanBuffer (used by AMSI) and EtwEventWrite (used by ETW). It monitors for suspicious API calls such as VirtualProtect, WriteProcessMemory, NtProtectVirtualMemory, or NtWriteVirtualMemory targeting these specific DLLs (amsi.dll and ntdll.dll), which is a common technique used by malware and offensive security tools to blind endpoint security and logging mechanisms.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
202
Correlates a Sysmon DriverLoad event matching known BTR.sys hashes with a subsequent System-process (PID 4) deletion of specific Defender binaries or WdFilter/WinDefend registry keys within a 10-second window — the definitive Defender self-destruction signature of the kernel primitive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6112
Detects outbound HTTP traffic indicative of pyCodeVx RAT check-in behavior. The rule identifies communication with ddnsfree.com C2 domains or requests containing the 'pyCodeVx' marker in the URL or User-Agent, coupled with a base64-encoded, fixed-format victim/session ID.
avatar
Renata Cardoso@rcardososec
avatar
Detections.ai Community
1 month ago
203
Detects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened.
There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive.
Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
002
Detects msedge.exe launched headless (--headless / --headless=new) with CDP remote debugging enabled (--remote-debugging-port=), a temp profile directory matching the launcher-edge- naming pattern, and window flags positioning it off-screen (--window-position=-32000,-32000, --window-size=1,1). This combination matches the TWINLOOT implant's technique of spawning a headless Edge instance with a Chrome DevTools Protocol connection, using the browser's authenticated same-origin session to proxy Microsoft Graph API C2 traffic so it blends in with legitimate browser network activity while remaining invisible on-screen. Excludes known browser-automation/CI framework parent processes and the --enable-automation flag to reduce false positives.
references:
- https://detections.ai/inspirations/01a01ade-da64-7718-8281-426118171583
- https://detections.ai/inspirations/01a01ade-d9a6-742d-8e2f-f60b5efce416
- https://detections.ai/inspirations/01a01ade-da04-700d-ba14-769eef28e475
- https://github.com/ontinue-research/threat-intel-iocs/blob/main/Public/2026-07-27-TWINLOOT-IOCs.md
- https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4015
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 months ago
3025
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory.
These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
000
Correlates the hardcoded BootClean.log creation-then-deletion lifecycle (performed by the System process) with a preceding anomalous or hash-matched BTR.sys driver load within a tight time window, reducing the otherwise high false-positive rate of alerting on the log artifact alone.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2011
Detects creation of an HKCU Run key value whose data references a temp or AppData temp path, consistent with the Windows persistence step of the botking implant after the build-time payload drop.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
0011
The following analytic detects Windows Filtering Platform filters that are added and configured to block outbound traffic for known EDR and security agent processes.
Tools such as EDRSilencer abuse WFP to disrupt outbound telemetry from EDR processes, which can bypass detections that only look for the tool process name.
This detection looks for WFP add events with a block action and EDR process names embedded in the hexdump-like Conditions field.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
105
Detects malicious DLL files attempting to masquerade as legitimate Microsoft Visual C++ runtime libraries (msvcp150.dll or msvcp160.dll) by identifying export markers and internal strings associated with the SynkLoader reflective PE loader.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
004
This rule monitors for the loading of a specific DLL file ('dsp_ippv2_x64.dll') by 'FineReader.exe'. This pattern may be indicative of DLL side-loading or hijacking attempts, where a legitimate application is used to load a malicious library.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
204
This rule monitors for potential privilege escalation or process manipulation by identifying non-system processes that interact with or follow execution patterns associated with MsMpEng.exe (Microsoft Defender) within a short timeframe. It specifically looks for a lower-privileged process triggering an activity related to the Defender service, followed immediately by a system-privileged process on the same device, which may indicate a bypass or injection technique used to gain or abuse system permissions.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
104
Detects additions or modifications to the Registry 'Run' keys in HKEY_CURRENT_USER, which are a common technique used by malware and adversaries to achieve persistence by automatically executing programs upon user logon.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
12011
This rule detects a multi-stage attack chain characteristic of the WordlistLoader/Amatera malware. It identifies the sequential occurrence of module unhooking (via CreateToolhelp32Snapshot), ETW bypass (via AddVectoredExceptionHandler), and remote process injection (via WriteProcessMemory, CreateRemoteThread, etc.) originating from the same process within a 15-minute window.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2013
Detects unauthorized, non-browser processes accessing sensitive Chromium-based browser credential files (e.g., 'Local State', 'Login Data', 'Cookies') followed by suspicious outbound network connections. This pattern is characteristic of credential-stealing malware (infostealers) like Amatera, Lumma, and Remus.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6113
Detects PDF documents that impersonate Notion invitation notifications and incorporate multiple redundant/overlapping URI links. This technique is used by the threat actor DOUBLOON DREDGER to facilitate EvilTokens device code harvesting campaigns.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects the presence of known malicious Rust crate archive files (arrayref-0.3.10.crate, proc-macro1-*, and related typosquatted package names) in a host's local Cargo registry cache, indicating the compromised dependency was fetched.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2010
Page 446 of 1866