Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects five or more distinct Windows user-account creation events (Event ID 4720) associated with the same actor and host within a one-hour time bucket, which may indicate unauthorized account creation for persistence or mass provisioning.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
806
Detects the use of net.exe or net1.exe to interact with administrator accounts, specifically looking for attempts to hardcode passwords in the command line or enabling/modifying domain accounts. This is a common pattern for local account persistence, privilege escalation, or lateral movement.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
105
Detects the execution or installation of the cloudflared utility via PowerShell, which is often used by adversaries to establish persistence or remote access tunnels (Cloudflare Tunnel). The rule triggers on process command lines involving 'cloudflared' and '1.ps1' keywords commonly associated with scripted deployment.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
205
Detects the creation of a local user account followed by the modification of the Winlogon SpecialAccounts\UserList registry key to hide the account from the Windows logon UI. This behavior is indicative of persistent access maintenance by adversaries, such as the Andariel threat group.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
5014
Detects anomalous child process creation by Zoom client executables (Zoom.exe, CptHost.exe, ZoomOpener.exe, zoom.us), specifically monitoring for command interpreters, script hosts, and browser processes, which may indicate exploitation of the Zoom client for code execution.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
10014
Detects creation of a zero-byte C:\ProgramData\desktop.ini by RtkNGUI64.exe, the crash artifact left behind when the implant's config has not been staged on a host.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects RtkNGUI64.exe creating or writing to tempcache.tmp during command-output staging, scoped to direct process attribution. The rename-away leg of this file's lifecycle is covered by the separate put-command drop-and-rename detection.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects command-history clearing and log-deletion events (history -c, PowerShell history wipe, Clear-EventLog, wevtutil cl) co-occurring with another suspicious indicator (credential access or lateral movement) on the same host within a 1-hour window, excluding scheduled group-policy retention jobs.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
13035
Detects RtkNGUI64.exe being launched via a WMI consumer using the 8.3 short-path form (Progra~1\Realtek\Audio), the same masquerading binary used for backdoor persistence.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects execution of command shell interpreters (cmd.exe, powershell.exe) associated with specific command-and-control opcodes indicative of the LxBaseRAT remote interactive shell subsystem.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
107
Detects the presence of API strings and function names in EDR telemetry associated with the LxBaseRAT keylogging module. The rule monitors for the usage of low-level keyboard hooks (WH_KEYBOARD_LL) and state polling functions (GetAsyncKeyState, GetKeyboardState) commonly used by malicious software to capture user input.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
107
Flags Zoom Workplace, VDI Client for Windows, and Zoom Rooms processes running a version below the ZOOMSDAY-patched thresholds (7.1.5/7.0.6 Workplace, 7.0.11/6.6.16 VDI, 7.1.0 Rooms/SDK), using semantic major.minor.patch comparison per product line so versions are never compared against the wrong product's threshold.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects the use of the 'copy /b' command to reconstruct an executable payload (Windowsupdate.exe) by concatenating split decoy files (header.doc and body.doc) typically located within a _rels directory, a technique associated with malware delivery chains like Operation QUICSILVER.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
106
This rule detects suspicious process execution chains originating from ScreenConnect (ConnectWise Control) service. It monitors for common living-off-the-land binaries (LolBins) or specific suspicious command-line patterns (e.g., encoded commands, credential discovery commands) being spawned by the ScreenConnect process, which is often abused by threat actors such as APT35/Magic Hound for remote access and persistence.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
1505
This rule detects a suspicious sequence of activities that potentially indicates an attempt to exploit Common Log File System (CLFS) vulnerabilities or manipulate cloud filter drivers for privilege escalation. The rule monitors for a correlation between Registry modifications involving Cloud Filter settings (HKLM\SYSTEM\CurrentControlSet\Services\CldFlt) and the creation or modification of specific CLFS-related files (.blf, .blf2, .regtrans-ms) occurring within a 10-minute window, with an optional check for symbolic link manipulation (NtCreateSymbolicLinkObject).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
15125
Detects browser-side storage artifacts (JWRCID, JwrExecutedInstructions, JwrCvvForm) persisted by the JWR phishing kit in a victim's browser session/local storage.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
007
Detects the creation of a zero-byte desktop.ini file within the C:\ProgramData directory. This pattern is indicative of a specific malware implant crash artifact, where the process attempts to create a configuration file using an OPEN_ALWAYS handle before experiencing a null pointer dereference.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
1016
Detects a Windows Error Reporting (WER) crash report for MsMpEng.exe whose fault signature matches the ShieldBreak exploit crash pattern, indicating the Defender process crashed as a byproduct of the TOCTOU exploitation attempt. Excludes routine crashes tied to signature/platform updates.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
7024
Detects endpoint network connections to the JWR phishing framework's static WebSocket path and worker script, used to carry AES-256-CTR encrypted exfiltration payloads via the JwrCrypto module.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Identifies core Windows subsystem binaries executing from any location other than System32. Binaries such as lsass.exe, winlogon.exe, services.exe and svchost.exe are never legitimately relocated or bundled by third-party software, so execution from an unexpected path indicates an adversary has placed a renamed or copied payload to blend in with normal process listings.

The detection uses a composite name-and-path key rather than checking either value independently, which catches relocation while permitting the genuine SysWOW64 copy of svchost.exe. Device paths reported by early-boot processes are normalised rather than excluded so that a genuine hit from a device path still fires. Scope is limited to Windows endpoints via DeviceInfo.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
2 months ago
1016
Detects the execution of an unsigned binary under a non-SYSTEM user context that directly spawns 'whoami.exe' which then runs as the SYSTEM account. This behavioral pattern is indicative of a successful local privilege escalation exploitation, where a malicious binary confirms its escalation by querying the current user identity in a SYSTEM shell. The rule includes exclusions for common administrative agents, such as the Microsoft Intune Management Extension, that may exhibit similar behavior due to periodic detection scripting.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
10117
Page 462 of 1866