Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects access to the FileZilla RecentServers.xml file, which contains historical server connection information. Attackers frequently target this file to extract stored FTP credentials, hostnames, and usernames for lateral movement or data exfiltration.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
001
Detects the execution of Windows Script Host (wscript.exe) where the Interactive mode is explicitly disabled in the script content or command line arguments. Disabling interactive mode is a common technique used by attackers to ensure malicious scripts run silently without triggering UI prompts or requiring user interaction.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
001
Detects Run key persistence for follow-on ACRStealer payloads (creator-ws.exe under ProgramData\Rapid, pgocvt.exe under ProgramData\TIEmounter) launched via a cmd /c start wrapper.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
507
Detects the creation of domain user accounts using the native 'net.exe' or 'net1.exe' utilities with command-line arguments that include '/add', '/dom', and naming conventions indicating 'backup_DA' or 'backup_EA'. This pattern is often associated with adversary attempts to establish persistence or backdoors using privileged service-like account names.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
206
Detects the installation or creation of a Windows service related to RustDesk, a remote access software application. This may indicate unauthorized installation or persistence setup of remote control tools by an adversary.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
206
Detects rapid execution of multiple system discovery commands (systeminfo, nltest, whoami, quser, ping) within a 15-minute window on a single host. Attackers often use these tools sequentially to gather intelligence about the environment, user identity, and network topography post-compromise.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
106
This rule detects the creation of a Windows service named 'Cloud Sync Service' using command-line tools like 'sc.exe' or 'New-Service', or via direct service event monitoring. This behavior is often associated with malware persistence mechanisms that use misleading names to blend in with legitimate software services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
21031
Detects network activity associated with the PureLogs Stealer, specifically connections to identified infrastructure hosting payloads on Pixeldrain and attempts to retrieve steganographic payloads via specific API endpoints.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects process hollowing/injection into wab.exe, MSBuild.exe, dllhost.exe, or rundll32.exe — suspended process creation combined with SetThreadContext or NtQueueApcThread on the same process within a 5-minute window, followed by an outbound connection to known ACRStealer C2 (49.13.169.214) or renewed browser credential-store access.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
307
Detects five or more distinct Windows user-account disable events (Event ID 4725) performed by the same actor on the same host within a one-hour time bucket, which may indicate unauthorized account access removal.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
107
Detects potential exploitation of the ScreenConnect SetupWizard.aspx to bypass authentication and create unauthorized administrative users. The rule monitors for the creation or modification of User.xml or Users.xml files in the ScreenConnect application directories, correlating these file events with suspicious process activity (such as cmd.exe or powershell.exe) or web requests to the SetupWizard.aspx endpoint.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
006
Detects completed administrative actions within the Cortex management console that result in a pause of endpoint protection. This action reduces security coverage on the targeted host and requires validation to ensure it aligns with authorized maintenance, troubleshooting, or incident response activities.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
807
The following analytic detects non-Chrome processes attempting to access the Chrome extensions file.
It leverages Windows Security Event logs, specifically event code 4663, to identify this behavior.
This activity is significant because adversaries may exploit this file to extract sensitive information from the Chrome browser, posing a security risk.
If confirmed malicious, this could lead to unauthorized access to stored credentials and other sensitive data, potentially compromising the security of the affected system and broader network.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
404
The following analytic detects the execution of the 'rmdir' command with '/s' and '/q' options to delete files and directory trees. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions and process metadata. This activity is significant as it may indicate malware attempting to remove traces or components during cleanup operations. If confirmed malicious, this behavior could allow attackers to eliminate forensic evidence, hinder incident response efforts, and maintain persistence by removing indicators of compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
004
The following analytic detects the suspicious creation of msmpeng.exe or mpsvc.dll in non-default Windows Defender folders. It leverages the Endpoint.Filesystem datamodel to identify instances where these files are created outside their expected directories. This activity is significant because it is associated with the REvil ransomware, which uses DLL side-loading to execute malicious payloads. If confirmed malicious, this could lead to ransomware deployment, resulting in data encryption, system compromise, and potential data loss or extortion.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
007
Detects C2Looper Rust-based backdoor by requiring at least 3 of 4 weak indicator categories: dynamic API resolution artifacts, v2 debug string, PE section layout, and Rust runtime strings; known hash is an optional fast-path only
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
305
Detects at least 3 distinct C2Looper-associated discovery commands (ipconfig /all, whoami /all, nltest /dclist, net group /domain "domain admins"/"domain computers", wmic product get name,version) executed by the same parent process within a 60 second window, reducing false positives from isolated legitimate admin usage of any single command.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
205
Detects the creation of a 'SystemIn.lnk' shortcut file within the Windows Startup folder, as well as the execution of temporary PowerShell scripts ('create_lnk_*.ps1') that use WScript.Shell to establish persistence. This behavior is associated with the QUICAgent backdoor attributed to Operation QUICSILVER.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
207
Detects the use of .NET AesCryptoServiceProvider in PowerShell scripts, which is frequently used by adversaries to decrypt embedded, obfuscated, or encrypted payloads within a script for malicious execution.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
008
Detects Zoom-related processes (zoom.us.exe, Zoom.exe, CptHost.exe) modifying registry keys within the Windows CapabilityAccessManager ConsentStore for webcam or microphone access. This activity indicates the system is recording the time a process initiated hardware access, potentially signaling unauthorized surveillance or post-compromise activity.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
9016
Detects TWINLOOT PyArmor 9.2.5-protected implant components via known file hashes combined with expected filesize range and filename/extension pattern (bootstrap-fat.pyc, pyarmor_runtime.pyd, .pyarmor.ikey, embedded vendor ZIP) to reduce false positives from renamed unrelated files with coincidental hash context
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Page 460 of 1866