Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
309
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
101
Detects activity associated with the MALFEX npm supply-chain campaign (also known as Overlord/movinlike). This rule performs a sweep for known malicious file hashes, suspicious process command lines, outbound network connections to malicious domains or IPs, and email communications from identified adversary-controlled accounts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
001
Detects activity associated with the MALFEX npm supply-chain campaign (also known as Overlord/movinlike). This rule performs a sweep for known malicious file hashes, suspicious process command lines, outbound network connections to malicious domains or IPs, and email communications from identified adversary-controlled accounts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
101
Detects the installation or execution of known MALFEX malicious packages via npm or Node.js, which are used as entry points for polyglot or disguised payload delivery.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
001
Detects the installation or execution of known MALFEX malicious packages via npm or Node.js, which are used as entry points for polyglot or disguised payload delivery.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
001
Detects the use of Mimikatz-style command-line arguments to manipulate Kerberos tickets, including ticket requests, purges, and golden/silver ticket creation attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the use of Mimikatz 'sekurlsa::pth' command for credential manipulation, or the occurrence of SMB/Windows administrative share access (ADMIN$, C$) potentially indicating lateral movement activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects potential lateral movement activity by identifying the execution of PsExec service components or common lateral movement tools (PsExec, WMIC, CMD) interacting with Windows administrative shares (via UNC paths or specific network ports 135, 139, 445). It specifically looks for process creation events associated with these tools and network activity indicative of remote administration. Legitimate administrative tools signed by Microsoft or known management software (SolarWinds, Tanium, Ivanti, IBM BigFix) are explicitly excluded.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit, and PowerShell) to delete Volume Shadow Copies, backup catalogs, or disable system recovery features. This is a common tactic used by ransomware and destructive actors to prevent system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects instances where a digitally signed process loads a DLL file from a user-writeable directory (such as Temp, AppData, Downloads, or Users\Public). This behavior is characteristic of DLL search order hijacking or side-loading, where an attacker attempts to load malicious code into a trusted, signed application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects common Cobalt Strike malleable profile named pipe creation events as well as network connections initiated by common LOLBins (Living Off the Land Binaries) that are unsigned, which is a common indicator of beaconing activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects the use of PowerShell to modify Windows Defender settings (e.g., disabling real-time monitoring, adding exclusions, or stopping services) using the Set-MpPreference cmdlet or service control commands. This technique is frequently utilized by ransomware actors, such as the ALPHV/BlackCat group, to neutralize security protections prior to executing malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
Detects the installation or execution of common Remote Monitoring and Management (RMM) tools, including AnyDesk, ScreenConnect, and TeamViewer, by monitoring process creation events. This behavior is indicative of social-engineering-based intrusions by the Scattered Spider (UNC3944/Octo Tempest) threat actor, who often impersonates IT support staff to convince users to run these tools for unauthorized remote access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects the execution of Grixba, a reconnaissance and inventory tool used by Play ransomware operators. The tool is designed to enumerate domain accounts, security software, backup solutions, and remote systems to facilitate reconnaissance prior to deploying encryption.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects the execution of regsvr32.exe with command line arguments containing 'scrobj.dll' and '/i:http'. This behavior indicates the abuse of the Windows Registry Server utility to load a remote COM scriptlet, a technique frequently observed in TA505 adversary activity to execute malicious payloads, such as the Get2 downloader or SDBbot RAT.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects high-frequency access to the root of the C:\ drive using access rights typically required for directory change notification. This behavior is a heuristic proxy for processes attempting to monitor the entire file system (e.g., via ReadDirectoryChangesW), often associated with post-compromise reconnaissance or surveillance of file operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
002
Detects remote thread creation (CreateRemoteThread or QueueUserAPC) into common Windows system processes (rundll32.exe or svchost.exe) originating from suspicious source processes. This activity is indicative of process injection techniques commonly utilized by Cobalt Strike beacons during post-exploitation, lateral movement, or ransomware deployment phases.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects registry modifications to CLSID InprocServer32 keys where the referenced DLL path resides in a non-standard, user-writable directory (e.g., AppData, Temp, ProgramData, Public, Recycle.Bin). This technique, known as COM Hijacking (T1546.015), is used by the Turla (also known as Snake, Secret Blizzard, Uroburos) threat group to achieve persistence by redirecting legitimate COM object references to malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
Detects Microsoft Outlook initiating outbound SMB or WebDAV network connections to external IP addresses. This behavior is indicative of exploitation of CVE-2023-23397, where a malicious reminder sound or attachment forces the victim's client to authenticate against an attacker-controlled remote share, potentially leaking NTLM hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects the execution of potentially malicious processes mimicking cryptocurrency or wallet applications (e.g., 'wallet', 'coin', 'crypto', 'exchange') that are launched from user-accessible directories like Downloads or Temp. The detection specifically looks for these processes spawning command-line interpreters (cmd.exe, powershell.exe) or proxy execution binaries (rundll32.exe), a behavior pattern characteristic of the AppleJeus campaign associated with Lazarus Group (Diamond Sleet).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Page 46 of 1870