Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule monitors firewall traffic logs to identify connections directed at managed internal endpoints originating from devices not tracked by the endpoint management system. It flags potential rogue or unauthorized devices performing multi-target reconnaissance or communication across the internal network.
avatar
Niril Ajay@nrl
avatar
Detections.ai Community
2 months ago
7016
This rule detects the loading of known vulnerable drivers on Windows systems by cross-referencing driver load events with a curated list of vulnerable drivers maintained by LOLDrivers.io. This technique, commonly referred to as 'Bring Your Own Vulnerable Driver' (BYOVD), is frequently used by adversaries to escalate privileges or perform kernel-mode exploitation.
avatar
0x 1337@0x1337
avatar
Detections.ai Community
2 months ago
40371
This rule monitors the Windows Application event log for critical Microsoft SQL Server (MSSQL) events. It detects server crashes, access violations, stack overflows, and high-severity (20+) errors. These events often indicate severe database corruption, underlying system instability, or potential exploitation attempts targeting the database engine.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Detects Windows Internet Shortcut (.url) files that contain suspicious lures and direct users to Microsoft device code authentication endpoints (devicelogin), characteristic of ARToken phishing campaigns hosted on anonymous SharePoint shares.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Flags direct registry staging of a Boot Bus Extender service (SERVICE_SYSTEM_START) whose Args value contains ':changelist', bypassing the Service Control Manager, where the driver image lies outside the Defender platform folder or uses a randomized 8-character filename — the SCM-bypass pattern used to stage BTR.sys for boot-time or immediate execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5114
This rule monitors network connections for traffic directed towards domains and IP addresses associated with a known malicious campaign distributing fake VPN browser extensions, as identified by Socket.dev. These domains and IPs are used for command and control or malicious communication by the browser extensions.
avatar
F S@Fsdr
avatar
Detections.ai Community
2 months ago
20128
Detects the botking RAT issuing Shell/ShellX/runscript commands that spawn powershell.exe from an implant-named parent process, matching the backdoor's remote command-execution capability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
10014
This rule detects the creation or modification of scheduled tasks or Windows services that reference 'fl_bridge' in their command line, service configuration, or task properties. This is often associated with persistence or execution mechanisms utilized by specific malware or unauthorized tools.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
003
This rule detects potential DLL side-loading activity where known legitimate executables, typically vulnerable to hijacking, are executed from suspicious directories (such as Temp, Downloads, or ProgramData) and subsequently load associated, potentially malicious DLLs.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
103
This rule detects potential DLL side-loading where 'FineReader.exe' loads the library 'dsp_ippv2_x64.dll'. It joins process creation and image load events to identify if the application was executed shortly before the library was loaded, which is a common indicator of side-loading activities.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
103
Detects the process 'Acrobatlog.exe' loading the DLL 'scansts.dll'. This pattern is frequently observed as a potential DLL side-loading or hijack attempt, where a non-standard or unexpected DLL is loaded by a specific process executable.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
003
Detects Python or PythonW processes loading an illegitimate 'msvcp150.dll' (masquerading as a Visual C++ redistributable) that simultaneously loads the .NET 'System.Management.Automation' assembly. This behavior is indicative of the SynkLoader technique, where a malicious native DLL is used as a bridge to execute PowerShell commands within the memory space of a Python process, bypassing traditional script-based detection.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
1 month ago
706
Detects the creation of a Windows Scheduled Task (Event ID 4698) that uses the 'InteractiveToken' LogonType, where the user specified to execute the task is different from the user who registered the task. This behavior is indicative of potential session hijacking or lateral movement techniques, such as those used by tools like 'atexec' or to facilitate PRT (Primary Refresh Token) theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
312
Detects Portable Executable (PE) files that reference or contain the string 'Warden.dll'. This DLL name is associated with the ShieldBreak proof-of-concept (PoC) which attempts to bypass Microsoft Defender by manipulating its defensive processes or environment.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
005
Detects the creation of a 'Report.wer' file, typically associated with Windows Error Reporting (WER), within a directory containing the string 'ShieldBreak'. This could indicate an attempt to utilize or manipulate WER for debugging or anti-forensic activities in non-standard locations.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
305
This rule monitors for potential privilege escalation or process manipulation by identifying non-system processes that interact with or follow execution patterns associated with MsMpEng.exe (Microsoft Defender) within a short timeframe. It specifically looks for a lower-privileged process triggering an activity related to the Defender service, followed immediately by a system-privileged process on the same device, which may indicate a bypass or injection technique used to gain or abuse system permissions.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
205
Detects instances where cmd.exe is executed within the context of the 'NT AUTHORITY\SYSTEM' account, but the parent process was not initiated by a SYSTEM account. This behavior is often indicative of privilege escalation where an adversary leverages a service or process to execute commands with elevated privileges.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
205
Detects the creation of a shortcut file named 'SystemIn.lnk' using PowerShell, a technique associated with the QUICSILVER malware to establish persistence. The rule monitors for PowerShell command-line arguments involving 'WScript.Shell' and 'CreateShortcut' alongside the specific file name.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
002
Detects the execution of pythonw.exe, which is used as a host process for the SynkLoader RAT, initiating outbound network connections to identified adversary-controlled C2 domains. This behavior is indicative of an established command-and-control channel for command retrieval and data exfiltration.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
002
Detects a malicious DLL component associated with SynkLoader, identified by specific exported functions (RunPowerShell, ExecutePowerShellCommand) and assembly metadata that facilitate executing PowerShell commands directly in memory.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
002
Detects the creation or modification of registry keys under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. These keys are commonly used by adversaries to achieve persistence by ensuring arbitrary programs or scripts execute automatically when the current user logs in.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
302
Page 448 of 1870