Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects a Zoom process (zoom.us/zoom.exe/CptHost.exe) writing to the Windows camera/microphone/screen-capture consent-store registry keys while no meeting network activity occurred within 15 minutes before or after, excluding pre-meeting device checks from Zoom Settings — a potential post-exploitation surveillance indicator following ZOOMSDAY RCE.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2011
Detects the ACRStealer BYOVD driver's ungated IOCTL 0x2205c0 being sent to \\.\DCRCVDRV_U by a non-management process, correlated within 2 minutes with termination of a security/EDR process, indicating kernel-level defense evasion via the vulnerable driver.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
809
Detects execution chains where archive utilities (7-Zip, WinRAR) or explorer.exe, when initiated from temporary or download directories, spawn common scripting engines (PowerShell, mshta.exe, cmd.exe, wscript.exe) that contain suspicious network-related or obfuscated command-line indicators.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
008
This rule detects potential command-and-control (C2) activity from the TWINLOOT malware, which utilizes Microsoft Teams TURN relay infrastructure to establish a reverse SOCKS5 tunnel. The detection identifies connections to 'worldaz-msit.relay.teams.microsoft.com' followed immediately by a SOCKS5 handshake pattern (05 01 00), indicating encapsulated tunneling within the relay communication.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects GhostTask-style hidden scheduled task persistence associated with the TWINLOOT Python implant framework. Legitimate scheduled tasks always write a security descriptor (SD) value under HKLM\...\Schedule\TaskCache\Tasks\<GUID>\SD alongside the corresponding HKLM\...\Schedule\TaskCache\Tree\<TaskName> entry. GhostTask abuses RegLoadAppKey/offreg.dll to build the TaskCache structure offline, producing a Tree entry and a Tasks\<GUID> key WITHOUT the accompanying SD value. The absence of the SD value combined with presence of the Tree entry is the key differentiator from normal task creation, which always writes SD. This technique is used by TWINLOOT to establish persistence while evading standard registry-event-based detections that rely on the presence of an SD value.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
Detects the TWINLOOT Python implant's self-update mechanism, in which a schtasks.exe process is spawned with '/Run' by a pythonw.exe parent process while referencing a reobf.json manifest on the command line, indicating the implant is relaunching itself via a scheduled task after fetching an updated/reobfuscated payload configuration.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
204
This rule detects instances where the Windows Defender Antivirus service (MsMpEng.exe) spawns common command-line shells (cmd.exe, powershell.exe, conhost.exe) while running under the SYSTEM context. This behavior is highly irregular for a security product and is indicative of process injection, exploit payload execution, or anti-tampering bypass attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
35242
Detects instances where a host that is not identified as a Domain Controller performs a DRSUAPI 'DRSGetNCChanges' request against another Domain Controller. This pattern is commonly associated with DCSync attacks, where an adversary mimics the Active Directory replication process to extract password hashes.
avatar
Collin Lairamore@Bollinmore
avatar
XQL Threat Forge
2 months ago
407
Detects instances where a host that is not identified as a Domain Controller performs a DRSUAPI 'DRSGetNCChanges' request against another Domain Controller. This pattern is commonly associated with DCSync attacks, where an adversary mimics the Active Directory replication process to extract password hashes.
avatar
Collin Lairamore@Bollinmore
avatar
Detections.ai Community
2 months ago
207
This rule detects the creation or modification of Registry values within the Windows 'Run' keys that contain the specific value name 'goopdate' and associated data containing the string 'work'. This pattern is indicative of a persistence mechanism used by specific threats to ensure their components, often disguised or related to malicious executable payloads, are launched automatically upon user logon.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
5016
Detects the use of curl.exe or curl to communicate with the malicious domain 'i.apee.my.id', initiated by a VS Code integrated terminal process. This behavior is indicative of malicious VS Code extensions exfiltrating data via a hidden terminal session.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
519
Detects the execution of native binaries, the creation/modification of Node-API (.node) files, or the loading of .node modules from Visual Studio Code extensions directories. This behavior is indicative of malicious VS Code extensions attempting to execute arbitrary native code for reconnaissance, persistence, or exfiltration.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
509
This rule detects instances of VS Code, code-server, or associated Node.js processes executing 'git config --get user.email'. This behavior is characteristic of malicious VS Code extensions (specifically 'evil-twin' extensions) attempting to perform developer reconnaissance by harvesting local Git identity information, which can then be exfiltrated.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
609
The following analytic detects creation of DLL files with names associated with phantom DLL hijacking opportunities.
These DLLs are usually absent from standard Windows installations, but legitimate Windows components or services may attempt to load them when they are present in expected search paths such as System32.
Phantom DLL hijacking involves placing a malicious DLL where a legitimate process will search for a non-existent dependency, allowing the attacker-controlled library to execute in that process context.
ShieldBreak is one example where the exploit redirects a privileged Defender-driven write into C:\Windows\System32\phoneinfo.dll and then triggers Windows Error Reporting so wermgr.exe loads the planted DLL at SYSTEM integrity.
If confirmed malicious, this activity can indicate preparation for code execution, persistence, or local privilege escalation through DLL search order hijacking.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
104
Detects outbound connections to the known Rust supply-chain C2 infrastructure, plus a lower-confidence rule for the broader Hostwinds range on port 9089.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
203
Detects binaries embedding both the hardcoded AES-128-GCM key 'i am botking' and the embedded RSA-2048 private key used for C2 command authentication
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects the botking RAT's C2 beacon: HTTPS POST with the 'i am botking' registration marker and form-urlencoded action=check polling, plus associated TLS/DNS indicators.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects the presence of known vulnerable drivers (rwdrv.sys and hlpdrv.sys) associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. Adversaries utilize these drivers to gain kernel-level access, allowing them to disable security software, escalate privileges, or maintain persistence.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
207
Detects ClickFix-style clipboard/paste-and-run execution: PowerShell, PowerShell ISE, mshta, or cmd spawned from the Windows Run dialog (explorer.exe/RunMRU) with IEX/Invoke-Expression/DownloadString/FromBase64String or mshta HTTP(S) invocation, consistent with the UNC5142 ClickFix lure delivering the DeviceManager RAT.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
17026
Detects processes attempting to interact with multiple browser binaries (chrome.exe or msedge.exe) across different standard application directories within a short time window. This behavior often indicates an adversary or malicious script probing for specific installed browsers to facilitate credential harvesting, configuration dumping, or session hijacking.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
004
Detects outbound C2 connections to known ACRStealer infrastructure IPs specifically from a process already flagged as hollowed/injected (wab.exe, MSBuild.exe, dllhost.exe) via a companion flowbit, rather than flagging all egress from these processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
008
Page 457 of 1866