Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the specific execution gate check utilized by WordlistLoader malware. The rule monitors ProcessApiCall events for OpenEventA or CreateEventA API calls using hardcoded, unique GUIDs known to be associated with this malware, ensuring high fidelity.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Identifies devices with missing or non-compliant Microsoft Defender security controls across Windows, Linux, and macOS endpoints.

The query reviews Microsoft Defender Vulnerability Management (TVM) secure configuration assessments and highlights devices where critical security capabilities are not functioning as expected, including:
Microsoft Defender Sensor
Sensor Data Collection
Defender Communications
Tamper Protection
Real-time Protection
PUA Protection
Cloud-delivered Protection
Security Definitions

Results are enriched with device exposure levels, machine groups, and sensor health status to assist security teams with remediation prioritization.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
206
Correlates BTR_CLI arbitrary-write invocations (Action 3) targeting System32\drivers with a resulting file write of a known-malicious hash (e.g., mimidrv.sys) or an unsigned/non-Microsoft-signed binary — detecting the kernel write primitive being used to plant a malicious driver into a protected directory.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
Detects network connection events to specific known malicious IP addresses (45.158.196.23, 45.158.196.184) over TCP port 8888. This activity is indicative of potential command and control (C2) communication or unauthorized remote access.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
307
Detects the creation or renaming of a file named 'pld.exe' within the AppData Local directory. This path is frequently used by malware to masquerade as legitimate applications and establish persistence while avoiding scrutiny.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
307
Detects periodic (beaconing) HTTP POST requests directed to '/api/beacon' from endpoints. The detection logic monitors for consecutive connections occurring within a 3-second interval, specifically searching for JSON payloads containing identification fields (id, user, host, pid) characteristic of C2Looper backdoor traffic.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
007
Detects multiple Kerberos pre-authentication failures (Event ID 4771) with failure code 0x18, indicating incorrect passwords, originating from the same source address for a specific user account within a ten-minute window, which may suggest brute-force or credential-stuffing activity.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
3011
Detects C2Looper's remote interactive shell and ShellExecuteW run-and-self-delete command execution, correlated with the c2_out.txt output-capture artifact.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
208
Detects ClickFix-style initial access where a Run-dialog-spawned interpreter (cmd.exe, powershell.exe, mshta.exe, cscript.exe) executes an encoded or obfuscated command line, consistent with clipboard-paste delivery of C2Looper.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
408
This rule monitors for successful certificate enrollments (Event ID 4886 and 4887) using sensitive certificate templates typically reserved for domain controllers or Kerberos authentication. It specifically alerts when these requests are made by user accounts that do not end in '$' (machine accounts) and are not known service accounts like 'CAService', which may indicate unauthorized attempts to obtain high-privilege credentials via AD Certificate Services (AD CS).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
317
This rule detects large file uploads (greater than 100MB) from endpoints to unmanaged or personal cloud storage services such as Google Drive, OneDrive, and Dropbox. This behavior may indicate unauthorized data exfiltration or the improper use of unapproved cloud storage platforms to move sensitive data outside of corporate control.
avatar
KQL Cowboy@KQLCowboy
avatar
Netskope Detection Engineering
2 months ago
409
Detects the execution of msiexec.exe to install specific MSI packages (ManageEngine-OpManager.msi or Advanced-IP-Scanner.msi) when initiated by explorer.exe. This pattern is indicative of user-driven execution, which may be part of an initial access or software deployment workflow.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
509
Detects the use of rundll32.exe to execute the MiniDump command against comsvcs.dll, a known technique used to dump process memory (such as LSASS) to a file for credential harvesting.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
309
Detects the execution of a malicious MSI installer file named '331.msi' masquerading as a 'PowerShell Cleaner' utility. The rule monitors for the execution of this MSI package and the subsequent staging of suspicious files, specifically 'cleaner.ps1' and 'archive6.zip', within the '%LocalAppData%\PowershellCleaner\script\' directory.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
000
Detects anomalous behavior by pythonw.exe where it interacts with screen locker assets or loads specific DLLs from non-standard locations, indicative of a PhishLocker-style fake lock screen being deployed to capture user credentials.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
000
This rule detects potential DLL sideloading by monitoring SumatraPDF.exe (SmartaPDF.exe) for the loading of a library named 'libmupdf.dll' from a non-standard or user-writable location. It combines process image load events with file activity patterns related to SumatraPDF cache and settings files, which are common indicators of malicious activity associated with this binary.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
24057
This rule detects activities associated with the C2Looper v2 backdoor, which achieves persistence and code execution by sideloading a malicious wtsapi32.dll into the OneDrive process. It also identifies subsequent beaconing behavior where the compromised OneDrive process communicates with GitHub-hosted infrastructure to exchange command and control state files (cmd.json, result.json, beacon.json) instead of using traditional dedicated C2 servers.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
000
Detects the execution of the temp_auto_push.bat tool, associated with the threat actor Void Dokkaebi, used to perform malicious commit amendments and code injection in source code repositories. The tool achieves this by manipulating the system clock to timestomp commit metadata, amending commits using 'git commit --amend --no-verify' to bypass security controls, and force-pushing the compromised history.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
000
Detects DLL search-order hijacking by monitoring for the execution of 'consent.exe' from non-standard directories (e.g., user-writable paths like %TEMP% or %APPDATA%) alongside the loading of specific DLLs (msimg32.dll, version.dll) from that same non-standard directory, which is indicative of malicious side-loading activity observed in Bumblebee and Akira intrusion campaigns.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
000
Detects the addition of a Microsoft Defender exclusion path targeting suspicious directories or executables that mimic legitimate Windows Defender installation paths (e.g., 'Microsoft\Windows Defender' or 'defender.exe'). This behavior is indicative of defense evasion, allowing attackers to hide malicious files from real-time scanning by bypassing security controls via PowerShell Set-MpPreference or WMIC.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
19111
The following analytic detects the creation of a Python path configuration (`.pth`) file in conjunction with a package installation process.
Path configuration files placed under `site-packages` or `dist-packages` are executed with every subsequent invocation of Python, allowing adversaries to achieve persistence on the victim endpoint regardless of build method or distribution type.
This technique was used by the threat actor group TeamPCP during the supply chain compromise of the `litellm` package.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
004
Page 454 of 1866