Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects execution of msiexec.exe involving specific command-line arguments (CA_Run_EA2AEBC3, Bin_lib_EA2AEBC3) often associated with malicious installers or library side-loading, correlated with the loading of 'lib.dll' by the msiexec process.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
102
Detects endpoint security scanner hits indicating the presence of msaRAT malware, specifically identifying its characteristic double-layer encryption scheme (DTLS transport paired with application-layer ChaCha-Poly1305 encryption) triggered by a 0xFE handshake frame.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
002
This rule detects potential infection by fake-VPN browser extensions associated with the 'Myxa VPN' campaign by monitoring for specific file paths and filenames linked to known malicious extension IDs. Additionally, it monitors for network connections to known command-and-control IP addresses associated with this campaign.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
2 months ago
11013
Detects logons using built-in default accounts (Administrator, Guest) or domain-admin accounts occurring outside an established baseline (new host, unusual time, first-ever interactive logon), repeated at least twice and excluding newly-provisioned accounts within their grace period or approved break-glass accounts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3027
Detects data exfiltration by the Kynx Stealer ChunkSender module which uses HTTP POST requests to a specific ingestion path.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4012
Detects C2Looper injecting shellcode into the legitimate winspool.drv module via a remote thread, excluding legitimate print subsystem processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Suricata signature detecting a Zoom annotation CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange PDU where a count field (count1-4) precisely exceeds 64, overflowing the 128-byte destination buffer — the wire-level trigger for the ZOOMSDAY buffer overflow, stack overflow, and heap-disclosure primitives (CVE-2026-53413).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
This rule detects potential multi-stage desktop takeover attacks by monitoring sequences of process execution within a 5-minute window. It looks for initial shell (explorer.exe or cmd.exe) spawning script-based tools (mshta.exe, wscript.exe, cscript.exe, powershell.exe, cmd.exe) with suspicious command-line arguments (extensions like .lnk, .url, .hta, or PowerShell-specific artifacts like 'IEX', 'DownloadString', or '-enc'). This is immediately followed by a secondary stage where PowerShell, cmd, or rundll32 are used to load external DLLs, register modules via regsvr32, or interact with AppData/Local/Temp directories, indicative of payload staging and execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
18113
Detects execution of the NetProvider network-monitoring utility from a non-standard install path or in close time proximity to an active videoconferencing session, consistent with PurpleDelta operator self-monitoring of network traffic during interviews.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects screen-recording or AI voice-transcription applications (iTop Screen Recorder, Krisp, Caption.Ed) running within 60 minutes of an active videoconferencing session, consistent with PurpleDelta operators recording or transcribing interviews or meetings to generate scripted answers.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects rapid self-deletion of the initial ACRStealer payload artifacts (Proper.a3x, BrowserMetrics) within 5 minutes of their creation by the setup_patched.exe/AutoIt execution chain — an indicator-removal behavior.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
Detects non-interactive PowerShell launched via the Sysnative path with -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command - reading commands from stdin — the ACRStealer payload's command-execution technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
304
Detects the ACRStealer Telegram Dead Drop Resolver handoff: a non-Telegram-client TLS/SNI contact into Telegram's IP range immediately followed by a DNS/TLS/HTTP connection to the resolved C2 domain res.explicittweak.cc.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects successful SYSTEM-level privilege escalation via the ShieldBreak exploit, which bypasses the fix for CVE-2026-50656 (RoguePlanet) on fully patched Windows 10, 11, and Server 2025 systems while Microsoft Defender is enabled. Fires when ShieldBreak.exe spawns cmd.exe running as NT AUTHORITY\SYSTEM with a whoami/system confirmation, correlated with Defender activity on the host within a 5-minute window.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
9017
Detects HTTP requests using JWR's e-commerce integration masquerade, where a base64-encoded 's' parameter carries harvested card data or a 'cart_data' parameter resolves to a non-Shopify checkout domain used to spoof the WebSocket C2 origin.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
This rule detects instances where the Windows Defender Antivirus service (MsMpEng.exe) spawns common command-line shells (cmd.exe, powershell.exe, conhost.exe) while running under the SYSTEM context. This behavior is highly irregular for a security product and is indicative of process injection, exploit payload execution, or anti-tampering bypass attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
11117
Detects an AutoIt3.exe/OptiDrive.exe process performing WMI sandbox-fingerprinting queries (Win32_DiskDrive, Win32_VideoController) followed within 15 minutes by access to browser credential files, consistent with ACRStealer's anti-analysis check preceding data collection.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects the execution of Windows processes where the file's web-origin metadata (Mark-of-the-Web) contains a referrer URL pointing to the public GitHub Desktop repository. This rule serves as a provenance and threat hunting signal to track the origin of binaries executed in the environment, identifying software potentially derived from this specific source repository.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
004
Detects high or critical severity audit events generated by Cortex XDR Collectors, which may indicate health, connectivity, processing, or configuration issues leading to gaps in security visibility.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
404
Detects DNS queries to definitionupdates.microsoft.com or the go.microsoft.com fwlink redirect used for WD update downloads, when the querying process is not a Windows system component. BlueHammer utilizes these definition updates as part of its exploit chain.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
003
Detects Windows Defender engine (mpengine.dll) or signature database files (*.vdm) being created by any process that is not a Windows Defender component.
BlueHammer extracts these files from the downloaded mpam-fe update package into a UUID-named subdirectory of %TEMP% as part of staging the TOCTOU privilege escalation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
003
Page 465 of 1866