Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the exact base64-encoded URL fragments used by the malicious proc-macro1 build.rs to obscure the C2 download URL (23.254.165.112:9089) prior to fetching a remote payload.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
108
This rule detects the creation of files with specific names '8bfa.zip' or '8bfa.bin' within the Windows AppData Local Temp directory. This behavior is indicative of a threat actor staging payloads or tools on a compromised system, typically as a precursor to execution or lateral movement.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
004
Detects read access to the Windows Registry keys associated with Outlook profile SMTP passwords. Attackers may attempt to extract these credentials to gain unauthorized access to email accounts.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
004
Detects instances where a non-SYSTEM process attempts to open a handle to winlogon.exe. Since winlogon.exe typically runs as SYSTEM and manages user sessions, unauthorized access to its process handle is often a precursor to credential dumping or token manipulation attacks aimed at escalating privileges to SYSTEM.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
001
This rule detects the creation of a Windows scheduled task named 'TaskHandler' using the schtasks.exe utility. The task is configured to execute a specific file, 'F7u00ex.exe', on system startup under the 'NT AUTHORITY\SYSTEM' account. This behavior is indicative of a persistence mechanism, often associated with the Spark RAT malware, which attempts to maintain a foothold on the system with high-level privileges.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
001
Detects the execution of Chrome or Microsoft Edge with remote debugging enabled (--remote-debugging-port) in a headless configuration (--headless=new). This combination is commonly used by automated scripts, scrapers, or potential malicious activity to interact with the browser remotely, which can be leveraged for data exfiltration, session hijacking, or automated attacks.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
2010
This rule monitors for the execution of msiexec.exe with command-line arguments involving 'update_ms.msi' specifically referencing 'Updates Verify' or 'LexSoft Ltd.', which may indicate the installation of potentially unauthorized or malicious software masquerading as legitimate updates.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
8010
Detects instances where the Windows Defender antimalware service (MsMpEng.exe) spawns common shell processes (cmd.exe, powershell.exe, pwsh.exe, or conhost.exe) while running under the SYSTEM account. This behavior is highly anomalous and indicative of potential exploitation involving privilege escalation via the Microsoft Defender process.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
70089
Detects C2Looper disabling Windows Error Reporting via registry modification to suppress crash dialogs, excluding common enterprise provisioning tools that legitimately configure the same keys.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
14015
Detects Active Directory replication events (Event ID 4662) targeting sensitive objects related to replication (e.g., Replication-Get-Changes-All). The rule filters out known Domain Controllers and designated replication service accounts to identify potential DCSync attacks or unauthorized directory replication attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
9013
Detects pythonw.exe executing from non-standard paths (ProgramData, AppData, or Temp) while loading netapi32.dll or ntdsapi.dll, consistent with the TWINLOOT implant's recon module performing NetAPI-based enumeration of domain controllers, admins, and domain trusts via DsEnumerateDomainTrusts and related calls, as observed being tasked by operators through the SharePoint dead-drop C2 channel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
109
Detects hash-matched BTR.sys driver loads that are validly signed by Microsoft but not initiated by a legitimate Windows Defender platform process (MsMpEng.exe/MpCmdRun.exe or the Defender Platform folder) — indicating the driver is being loaded by an unauthorized process to abuse its kernel-level file/registry operation primitive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects the Rust rustls custom AcceptAll ServerCertVerifier pattern (all three verify methods returning success unconditionally) used by the proc-macro1 payload to bypass TLS certificate validation when fetching its remote payload.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects the execution of the QUICAgent backdoor (Windowsupdate.exe) from an AppData folder path. The rule monitors for this specific process name, which has been associated with C2 activity including hostname and username enumeration.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
6012
This rule Hunts Microsoft Defender for Endpoint DeviceFileEvents for .aspx/.ashx/.asmx files created by w3wp.exe (the IIS worker process) inside SharePoint-specific directories (wss\VirtualDirectories, Web Server Extensions, TEMPLATE\LAYOUTS, App_Code, App_Web, \bin\) — a classic webshell-drop pattern used once an attacker has already gained code execution on the server. It excludes benign SYSTEM/TrustedInstaller writes of default.aspx/upgrade.aspx to cut noise from normal patching/upgrade activity. This is a post-exploitation signature — it doesn't detect the exploit itself, only the artifact an attacker typically drops afterward.

CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort.

Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
972115
Detects TWINLOOT persistence mechanisms observed in the TWINLOOT Python implant framework, including COM hijacking via a scriptlet (.sct) reference written to the TypeLib registry key for CLSID {EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} version 1.1 (win32/win64), and the creation of a Run key value named 'UserExperienceSync' under CurrentVersion\Run for autorun persistence.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
708
Detects PowerShell or pwsh processes spawned from Teams.exe with command-line arguments indicative of remote download and execution (e.g. Invoke-WebRequest, curl, encoded commands, IEX, Invoke-Expression, Expand-Archive of a zip archive). This pattern matches the TWINLOOT campaign's initial access chain, in which victims are lured via fake Microsoft Teams messages (T1566.004) into launching malicious content that triggers PowerShell execution (T1059.001) from within the Teams process, consistent with user execution of a malicious link or file (T1204.002).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
208
Detects anomalous pythonw.exe execution from non-standard installation paths that exhibits a fan-out pattern of network connections to multiple sensitive internal administrative ports (445, 3389, 5985, 22, 1433, 135, 389). This behavior is characteristic of lateral movement using a SOCKS5 proxy tunnel, such as the activity observed in the TWINLOOT campaign where implants pivot through reverse tunnels to access internal resources.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
608
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 months ago
5013
Detects instances where the SQL Server process (sqlservr.exe) initiates a child process that is a known command-line tool, script interpreter, or utility often used in living-off-the-land attacks, or when a child process is spawned from suspicious directory paths such as AppData, Temp, or Windows\Temp.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects malicious PDF attachments that masquerade as DocuSign remittance advice notifications. These PDFs contain embedded hyperlinks (via /URI or /Link action annotations) designed to redirect users to malicious external sites rather than legitimate DocuSign services, commonly used in phishing campaigns.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Page 453 of 1870