Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects hash-matched BTR.sys driver loads that are validly signed by Microsoft but not initiated by a legitimate Windows Defender platform process (MsMpEng.exe/MpCmdRun.exe or the Defender Platform folder) — indicating the driver is being loaded by an unauthorized process to abuse its kernel-level file/registry operation primitive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects the Rust rustls custom AcceptAll ServerCertVerifier pattern (all three verify methods returning success unconditionally) used by the proc-macro1 payload to bypass TLS certificate validation when fetching its remote payload.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects the execution of the QUICAgent backdoor (Windowsupdate.exe) from an AppData folder path. The rule monitors for this specific process name, which has been associated with C2 activity including hostname and username enumeration.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
6012
This rule Hunts Microsoft Defender for Endpoint DeviceFileEvents for .aspx/.ashx/.asmx files created by w3wp.exe (the IIS worker process) inside SharePoint-specific directories (wss\VirtualDirectories, Web Server Extensions, TEMPLATE\LAYOUTS, App_Code, App_Web, \bin\) — a classic webshell-drop pattern used once an attacker has already gained code execution on the server. It excludes benign SYSTEM/TrustedInstaller writes of default.aspx/upgrade.aspx to cut noise from normal patching/upgrade activity. This is a post-exploitation signature — it doesn't detect the exploit itself, only the artifact an attacker typically drops afterward.

CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort.

Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
972115
Detects TWINLOOT persistence mechanisms observed in the TWINLOOT Python implant framework, including COM hijacking via a scriptlet (.sct) reference written to the TypeLib registry key for CLSID {EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} version 1.1 (win32/win64), and the creation of a Run key value named 'UserExperienceSync' under CurrentVersion\Run for autorun persistence.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
708
Detects PowerShell or pwsh processes spawned from Teams.exe with command-line arguments indicative of remote download and execution (e.g. Invoke-WebRequest, curl, encoded commands, IEX, Invoke-Expression, Expand-Archive of a zip archive). This pattern matches the TWINLOOT campaign's initial access chain, in which victims are lured via fake Microsoft Teams messages (T1566.004) into launching malicious content that triggers PowerShell execution (T1059.001) from within the Teams process, consistent with user execution of a malicious link or file (T1204.002).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
208
Detects anomalous pythonw.exe execution from non-standard installation paths that exhibits a fan-out pattern of network connections to multiple sensitive internal administrative ports (445, 3389, 5985, 22, 1433, 135, 389). This behavior is characteristic of lateral movement using a SOCKS5 proxy tunnel, such as the activity observed in the TWINLOOT campaign where implants pivot through reverse tunnels to access internal resources.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
608
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 months ago
5013
Detects instances where the SQL Server process (sqlservr.exe) initiates a child process that is a known command-line tool, script interpreter, or utility often used in living-off-the-land attacks, or when a child process is spawned from suspicious directory paths such as AppData, Temp, or Windows\Temp.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects malicious PDF attachments that masquerade as DocuSign remittance advice notifications. These PDFs contain embedded hyperlinks (via /URI or /Link action annotations) designed to redirect users to malicious external sites rather than legitimate DocuSign services, commonly used in phishing campaigns.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
The following analytic detects WerMgr.exe (Windows Error Reporting) spawning a child process running at SYSTEM integrity level.
WerMgr.exe normally runs at the integrity level of the reporting user or as a background SYSTEM-owned service that does not launch interactive children.
In the ShieldBreak exploit, WerMgr.exe is manually triggered via the QueueReporting scheduled task and loads an attacker-planted phantom DLL (phoneinfo.dll), which then spawns an elevated shell.
If confirmed malicious, this activity indicates successful local privilege escalation to SYSTEM.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
108
Detects creation of the ':changelist' configuration stream or a feedback (*.dat) stream written onto a .sys driver file itself, distinguishing the abuse pattern (feedback stream on the driver) from legitimate Defender remediation, which writes feedback to a standalone ProgramData path.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
316
Detects SYSTEM processes initiated by non-service user accounts from user-writable locations such as AppData, Temp, Public, ProgramData, and Downloads. This behavior may indicate local privilege escalation and is relevant to post-exploitation activity associated with CVE-2026-68820.
avatar
Tun Tun Naing@tuntun
avatar
Detections.ai Community
2 months ago
46180
Correlation detection for the PureLogs Stealer / fake Adobe Sign campaign. Fires when 3+ of 6 distinct attacker behaviors (Downloads-sourced 'output_*.js' execution via wscript/cscript, UserinitMprLogonScript persistence pointing at a .js payload, PowerShell fileless env-var payload reconstruction via [System.Environment]::GetEnvironmentVariable+IEX, in-memory .NET Assembly.Load without a disk-based .dll/.exe argument, PowerShell-initiated PixelDrain PNG retrieval, and PowerShell-initiated C2 traffic to vm180012.hosted-by.qwins.co) occur on the same host within a 15-minute window. All network/PowerShell legs are scoped to powershell.exe specifically to avoid flagging benign browser traffic to the legitimate PixelDrain file-sharing service.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects a suspicious process chain where 'conhost.exe' with the '--headless' command-line argument spawns 'cmd.exe', which subsequently executes 'powershell.exe'. This pattern is often indicative of automated execution, lateral movement, or malicious script deployment using obfuscated or hidden command-line execution methods.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
306
Detects modifications to the UserInitMprLogonScript registry value that point to suspicious locations or file types (e.g., AppData, .js, .vbs). This registry key is commonly used for persistence by executing a script at user logon. The rule excludes common legitimate paths like NETLOGON or SYSVOL.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
306
Detects file access events targeting the Mozilla Thunderbird profile directory on Windows systems, which may indicate unauthorized collection or theft of local email data, archives, and account configuration files.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
003
Detects file system access to the ProtonVPN local configuration directory. This directory may contain sensitive data, such as cached credentials or session information, which could be targeted by unauthorized actors to facilitate credential theft or session hijacking.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
003
Detects the creation of a registry RunOnce key pointing to an executable named 'vlc.exe' located within a user's temporary directory. This pattern is commonly associated with persistence mechanisms where malware masquerades as a legitimate application to gain execution upon user login.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
003
Detects the deletion of specific staging files (8bfa.zip or 8bfa.bin) within the Windows user's local Temp directory, often associated with adversary cleanup activities after staging data or tools.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
003
Detects known malicious stage-2 payload binaries dropped by the compromised proc-macro1/arrayref Rust supply-chain attack via hash, size, and file-type match.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Page 450 of 1866