Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

The following analytic identifies the creation of executables or scripts in temporary file paths on Windows systems. It leverages the Endpoint.Filesystem data set to detect files with specific extensions (e.g., .exe, .dll, .ps1) created in temporary directories (e.g., \windows\Temp\, \AppData\Local\Temp\).
This activity can be significant as adversaries often use these paths to evade detection and maintain persistence.
If confirmed malicious, this behavior could allow attackers to execute unauthorized code, escalate privileges, or persist within the environment, posing a significant security threat.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
209
Detects TWINLOOT's fake lock screen credential harvesting technique, where the implant creates a window using highly unique class names (launcher_black_screen_31337, launcher_fake_lockscreen_view) to simulate a Windows lock screen and then calls GetUserNameExW to capture the logged-on user's credentials without validation, feeding harvested credentials into subsequent lateral movement.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects the loading of unsigned .node files.
Adversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack.
.node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code.
This technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
001
The following analytic detects mpclient.dll, the Windows Defender client API library, being loaded by a process that is not part of the Windows Defender platform.
mpclient.dll exposes the API surface used to drive on-demand Defender scans (IOAV, MpScan). In the ShieldBreak exploit, the attacker binary loads mpclient.dll directly and calls its scan APIs against an object-manager path in order to trigger a Defender scan against attacker-controlled content as part of a race condition targeting Defender's placeholder-hydration behavior.
If confirmed malicious, this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
207
Detects a Ray raylet, gcs_server, or dashboard process spawning a calculator process (a near-certain PoC/exploit indicator) or a shell child process carrying suspicious network, encoding, or reverse-shell command-line indicators, consistent with post-exploitation of CVE-2025-62593. Known-legitimate pipeline package-install commands are filtered out to reduce noise from normal Ray job workers.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
2 months ago
1013
Detects the creation of a scheduled task via the Windows COM interface, a technique used by malware like SynkLoader to bypass command-line monitoring (e.g., schtasks.exe). The rule monitors Windows Security Event IDs 4698 and 4702 for tasks configured to trigger on logon that execute script-based content (Python or PowerShell) from user-writable directories.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
102
This rule monitors for successful certificate enrollments (Event ID 4886 and 4887) using sensitive certificate templates typically reserved for domain controllers or Kerberos authentication. It specifically alerts when these requests are made by user accounts that do not end in '$' (machine accounts) and are not known service accounts like 'CAService', which may indicate unauthorized attempts to obtain high-privilege credentials via AD Certificate Services (AD CS).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
209
Detects Active Directory replication events (Event ID 4662) targeting sensitive objects related to replication (e.g., Replication-Get-Changes-All). The rule filters out known Domain Controllers and designated replication service accounts to identify potential DCSync attacks or unauthorized directory replication attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
209
Detects network requests targeting 'chickplaybox.com', which is associated with a phishing campaign masquerading as the Adobe Sign platform. This rule monitors both cleartext HTTP host headers and TLS SNI fields to identify attempts to access the malicious domain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects PureLogs Stealer payload binaries by identifying specific artifacts including a hardcoded nibble-decoding alphabet, minimal PE imports, and high-entropy sections containing obfuscated Windows API strings like GetProcAddress, kernel32.dll, and ntdll.dll.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
The following analytic detects non-Chrome processes accessing the Chrome "Local State" file, which contains critical settings and information. It leverages Windows Security Event logs, specifically event code 4663, to identify this behavior.
This activity is significant because threat actors can exploit this file to extract the encrypted master key used for decrypting saved passwords in Chrome.
If confirmed malicious, this could lead to unauthorized access to sensitive information, posing a severe security risk.
Monitoring this anomaly helps identify potential threats and safeguard browser-stored data.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
008
Detects Windows system binaries and commonly abused native LOLBins executing from outside their expected system directories, indicating a renamed, relocated, or imposter copy consistent with masquerading, DLL side-loading staging, or process-name spoofing.
avatar
Collin Lairamore@Bollinmore
avatar
XQL Threat Forge
2 months ago
4011
Detects WordlistLoader binaries containing the decode-and-execute routine that reconstructs shellcode via a wordlist mapping or UUID string array, then marks it RWX before invoking the entry point
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects unexpected child processes spawned by Rust build tools (cargo/rustc) that initiate network connections during build processes. This rule specifically monitors for instances where the build process performs network-related activities associated with build scripts (build.rs) or cargo build commands, which may indicate malicious dependency injection or build-time exfiltration.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
205
This rule detects PowerShell processes performing file downloads using common commands (such as Invoke-WebRequest, BITS, or Certutil) and saving or targeting files within user-profile specific directories (AppData). This behavior is often indicative of an adversary staging malicious tools or payloads in a writeable user directory.
avatar
Subash Ghimire@iamsubashg
avatar
Detections.ai Community
2 months ago
17171
This rule detects the execution of 'cmd.exe' with specific arguments 'start /max' used to open a file named 'TrainingAnnouncement.pdf'. This pattern is associated with Operation QUICSILVER, where attackers use this specific command line invocation to masquerade a malicious process or backdoor installation as a benign document opening event.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
209
This rule detects a suspicious sequence of activities that potentially indicates an attempt to exploit Common Log File System (CLFS) vulnerabilities or manipulate cloud filter drivers for privilege escalation. The rule monitors for a correlation between Registry modifications involving Cloud Filter settings (HKLM\SYSTEM\CurrentControlSet\Services\CldFlt) and the creation or modification of specific CLFS-related files (.blf, .blf2, .regtrans-ms) occurring within a 10-minute window, with an optional check for symbolic link manipulation (NtCreateSymbolicLinkObject).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
43074
This rule detects PowerShell commands that programmatically create a Windows shortcut (.lnk file) targeting a startup folder or mimicking Windows update processes. This behavior is indicative of an adversary attempting to establish persistence by creating a shortcut that executes a malicious script or binary upon user login or system startup, often associated with the QUICSILVER campaign.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
809
Detects an Exchange server initiating outbound SMB (port 445) connections to non-private (external) IP addresses. This behavior is highly characteristic of PetitPotam (MS-EFSR) coercion, where an attacker forces the server to authenticate to an external, attacker-controlled UNC path to capture NTLM authentication credentials or relay them to other network resources.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
9114
Detects execution of pythonw.exe (windowless Python) with the LAUNCHER_BG_CHILD=1 environment marker present on the command line alongside TWINLOOT-specific staging marker filenames (.agent.lock, .vendor.ok, .vendor.stamp, .reobf.manifest, client_id.txt). TWINLOOT is a modular Python implant that relaunches itself windowlessly via pythonw.exe, extracts a vendor ZIP, and uses these marker files to track staging state during its bootstrap and PyArmor-protected launcher stages, while abusing Microsoft 365/Azure services for C2.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects creation of a mandatory profile hive (NTUSER.MAN) matching the size produced by the RegLoadAppKeyW -> ORCreateKey/ORSetValue/ORSaveHive offreg.dll API sequence used to forge an offline registry hive for persistence, as observed with the TWINLOOT Python implant. TWINLOOT builds the offline hive via offreg.dll (RegLoadAppKeyW, ORCreateKey, ORSetValue, ORSaveHive) with Run key or COM hijack values baked in, then writes it to %USERPROFILE%\NTUSER.MAN so Windows loads it in preference to NTUSER.DAT at the next user logon, achieving persistence with no registry events, no admin privileges, and no visibility to standard tooling. Tightened to exclude the process image when it is a known legitimate profile-management or provisioning tool (USMT, SCCM, Intune Management Extension) that also uses offreg.dll to build NTUSER.MAN during normal mandatory/roaming profile deployment.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Page 452 of 1866