Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects the termination of specific security-related processes (e.g., antivirus services) shortly after a specific driver, 'ardrv.sys', is loaded on a Windows system. This sequence is characteristic of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where an adversary loads a signed but vulnerable kernel driver to gain elevated privileges, which they then use to disable or terminate security monitoring processes.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
003
Detects processes attempting to open a handle to the Local Security Authority Subsystem Service (LSASS) process with read-capable access rights (0x1010 or 0x1410). These access rights are commonly associated with credential dumping tools like Mimikatz, which read LSASS process memory to extract credentials. Legitimate system processes such as wininit.exe and services.exe are excluded to reduce noise.
avatar
Renata Cardoso@rcardososec
avatar
Detections.ai Community
2 months ago
308
Identifies devices with software versions affected by CVE-2026-45321 or devices running TanStack related packages identified via vulnerability management and software inventory data.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
001
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
204
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
304
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
004
Detects ERAAgent.exe performing suspicious dynamic API resolution for functions commonly used by the SLEEPWALKER malware (VirtualProtect, SetSecurityDescriptorDacl, and CryptGenRandom). By resolving these functions at runtime via GetProcAddress rather than including them in the static import table, the malware attempts to evade detection and analysis.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
004
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
104
Detects various indicators of Microsoft Connection Manager Profile Installer execution
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
004
Detects indicators of the PhishLocker credential harvester, specifically the loading of fake Microsoft Visual C++ runtime DLLs from non-standard (user-writable) paths and unauthorized access to Windows lock screen images by Python-based processes.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
407
Detects behavioral indicators associated with the ChocoShell malware, a fileless PowerShell-based infostealer. The rule monitors for malicious command-line activity including AMSI bypass, credential theft from Token Broker and WLAN profiles, disabling of Microsoft Defender signatures, and communication with local API endpoints typical of the CornFlake controller.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
507
Correlates email delivery, URL click telemetry, endpoint network connections, and process execution evidence for one or more suspicious URLs or domains.

This query helps analysts identify who received an email containing a target URL, who clicked it, whether the URL was observed on managed endpoints, which devices were involved, and what processes initiated related network or command-line activity.

It is useful for phishing investigations, malicious URL exposure reviews, post-delivery impact checks, campaign scoping, and confirming whether a user interaction led to endpoint activity.

The query uses Microsoft Defender XDR advanced hunting tables including EmailUrlInfo, EmailEvents, UrlClickEvents, DeviceNetworkEvents, and DeviceProcessEvents. Microsoft documents UrlClickEvents as containing Safe Links click information from email messages, Teams, and Office apps, populated by Defender for Office 365.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
15026
Detects access to SQL developer tool configuration files (connections.json, product-preferences.xml) followed by a decryption utility, used by CISA's red team to recover cleartext database credentials from a targeted workstation.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
203
Detects the execution of a process named ShieldBreak.exe by monitoring device process events.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
106
This rule detects processes or file activities involving path strings related to Windows Defender shadow scan operations, specifically targeting the 'WD_SHADOW_' and 'WD_SCAN\BERLIN' named object patterns. These artifacts are typically associated with security software internal processes or potential attempts by adversaries to interact with or monitor Windows Defender's scanning activities.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
306
Detects changes to the "ServiceDLL" value related to a service in the registry.
This is often used as a method of persistence.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
Detects ClickFix-style initial access where a Run-dialog-spawned interpreter (cmd.exe, powershell.exe, mshta.exe, cscript.exe) executes an encoded or obfuscated command line, consistent with clipboard-paste delivery of C2Looper.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
60037
Detects mass deletion of files related to backups, archives, or disaster recovery across multiple distinct devices within a short timeframe. This behavior is indicative of an adversary attempting to destroy backup infrastructure to prevent system recovery following a disruptive event such as ransomware deployment.
avatar
Seb Cantar@sebcantar
avatar
Detections.ai Community
1 month ago
003
This rule detects suspicious file downloads initiated by common browsers from a specific remote domain ('reficon.pro') associated with '/vizio.com/'. It enriches this activity by checking for prior beaconing activity to 'stats.us3.org' (often used for Matomo analytics), which may indicate a multi-stage attack where an initial profiling beacon precedes a malicious payload download.
avatar
Seb Cantar@sebcantar
avatar
Detections.ai Community
1 month ago
103
Detects instances where the Google Chrome browser is executed with flags that disable the sandbox security feature, such as --no-sandbox and --allow-no-sandbox-job. This configuration is often used by adversaries to facilitate credential dumping from the browser by bypassing sandbox restrictions that typically prevent unauthorized process memory access.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
208
msiexec.exe running as SYSTEM, spawned by a script/task host, with no installer package.

Procedure is currently being used by Lazarus group in conjunction with CVE-2026-68820

Ref https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
avatar
Sam Harrison@sect0rcybersec
avatar
Detections.ai Community
2 months ago
17174
Page 447 of 1870