Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects C2Looper sideloading a malicious wtsapi32.dll from a non-System32 path by terminating and relaunching the legitimate OneDrive.exe process to load it.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
504
Detects C2Looper injecting shellcode into the legitimate winspool.drv module via a remote thread, excluding legitimate print subsystem processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
204
Detects C2Looper disabling Windows Error Reporting via registry modification to suppress crash dialogs, excluding common enterprise provisioning tools that legitimately configure the same keys.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
204
Detects presence of persona-fabrication and identity-fraud enablement software (Wavebox, MEmu, eSIM Plus, Blacktel, insertFace, TrustID Card) via process, network, or file-system artifacts on an endpoint, consistent with PurpleDelta identity-fraud tradecraft.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
304
Detects execution of face-swapping or deepfake software, excluding known legitimate virtual-background/video-filter tools, consistent with PurpleDelta operators disguising their identity during video interviews.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
304
Detects the compiled ShieldBreak C++ proof-of-concept exploit binary via embedded source/resource path strings and PE header, indicating local possession or execution of the CVE-2026-50656 Defender bypass PoC.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5022
Detects loading of Warden.dll — the Defender-bypass component of the ShieldBreak exploit — when unsigned or not signed by Microsoft, excluding legitimate signed Defender platform update binaries.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
10022
The following analytic identifies non-Chrome processes accessing the Chrome user data file "login data."
This file is an SQLite database containing sensitive information, including saved passwords.
The detection leverages Windows Security Event logs, specifically event code 4663, to monitor access attempts.
This activity is significant as it may indicate attempts by threat actors to extract and decrypt stored passwords, posing a risk to user credentials.
If confirmed malicious, attackers could gain unauthorized access to sensitive accounts and escalate their privileges within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
003
The following analytic detects the use of the taskkill command in a process command line to terminate several known browser processes, a technique commonly employed by the Braodo stealer malware to steal credentials. By forcefully closing browsers like Chrome, Edge, and Firefox, the malware can unlock files that store sensitive information, such as passwords and login data. This detection focuses on identifying taskkill commands targeting these browsers, signaling malicious intent. Early detection allows security teams to investigate and prevent further credential theft and system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
003
This rule detects the loading of a driver by system utilities (drvinst.exe, pnputil.exe, setupapi.dll, or System process) shortly after a PnP (Plug and Play) device connection event. It specifically flags instances where the driver file is located in suspicious directories (Windows/Temp, Users/Public, AppData/Local/Temp) or the file does not have a .sys extension, which are common indicators of malicious driver installation or BYOVD (Bring Your Own Vulnerable Driver) tactics.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
4016
Detects the use of the BITSAdmin utility to create, add, resume, or complete download jobs, which may indicate an adversary attempting to download malicious files or tools onto a system.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
6024
Detects vssvc.exe opening a handle to MsMpEng.exe.
In the RedSun exploit, VSS participates in the cloud-file restore race that directs WD to write through the NTFS junction.
This handle acquisition is observed at the exact moment of exploitation.
vssvc querying MsMpEng is not expected in normal operation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
004
Detects ACRStealer C2 data-transfer bursts (outbound credential-data exfiltration >100KB, inbound follow-on payload >1MB) correlated with prior credential-sweep and process-injection-stage flowbits, rather than raw transfer size alone.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a malformed/high-entropy repeated-label DNS query pattern used by ACRStealer as a connectivity canary check prior to establishing C2.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects sandbox/VM fingerprinting via combined Win32_DiskDrive and Win32_VideoController WMI queries from the same process/host within a short window — anti-analysis behavior observed in the ACRStealer AutoIt payload prior to execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects CoolClient's data-collection module: co-occurring keylogging hook installation, clipboard access, and Chromium credential-store file access from an unsigned/non-OS-vendor process.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
7011
Detects the creation of .php files within the wp-content/uploads directory tree by common web server or PHP-FPM processes. This behavior is indicative of an adversary attempting to drop a web shell via file upload bypass vulnerabilities, such as those exploiting MIME-type manipulation.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
415
Detects StopAndProtect malware binaries via the hardcoded developer source path string, validated against PE format or a known sample hash.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
This rule detects suspicious activity where an executable named 'new.exe' located in a temporary directory initiates a process image load of a non-DLL file or an unspecified module. This pattern is indicative of reflective code loading or process injection, where a malicious binary attempts to execute payloads directly in memory rather than relying on standard DLL loading mechanisms.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
10022
Potential exploitation of JetBrains TeamCity (Unauthenticated RCE, CVE-2026-63077) looking for suspicious child processes spawned by TeamCity services.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6020
Detects coordinated activity where a PowerShell process executes multiple distinct administrative utilities (such as wevtutil, vssadmin, wbadmin, or bcdedit) to perform destructive actions like clearing event logs, deleting shadow copies, or disabling system recovery settings. This rule uses correlation to identify sequences of at least three distinct commands and utilities, reducing false positives associated with single administrative tasks.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
005
Page 463 of 1866