Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,173 detections

Detects registration of an unrecognized cloud sync provider combined with placeholder file creation within a short window, consistent with ShieldBreak's TOCTOU race staging technique. Excludes signed installs/re-registrations of known legitimate cloud sync clients (OneDrive, Dropbox, Google Drive, Box).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5015
Detects CoolClient process injection into a suspended synchost.exe instance via remote thread creation and thread-context redirection.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1108
The following analytic detects the creation of screen capture files by the Braodo stealer malware. This stealer is known to capture screenshots of the victim's desktop as part of its data theft activities. The detection focuses on identifying unusual screen capture activity, especially when images are saved in directories often used by malware, such as temporary or hidden folders. Monitoring for these files helps to quickly identify malicious screen capture attempts, allowing security teams to respond and mitigate potential information exposure before sensitive data is compromised.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
002
This rule detects potential SQL injection attacks and anomalous request patterns targeting the '/api/session/reset_password' IIS API endpoint. It identifies common SQL injection payloads within the HTTP request body and flags excessive requests to this endpoint that lack expected JSON structure, which may indicate automated scanning or credential stuffing attempts.
avatar
KQL Cowboy@KQLCowboy
avatar
Detections.ai Community
2 months ago
203
This rule detects large file uploads (greater than 100MB) from endpoints to unmanaged or personal cloud storage services such as Google Drive, OneDrive, and Dropbox. This behavior may indicate unauthorized data exfiltration or the improper use of unapproved cloud storage platforms to move sensitive data outside of corporate control.
avatar
KQL Cowboy@KQLCowboy
avatar
Detections.ai Community
2 months ago
303
Detects potential DeadLock ransomware activity by correlating a high volume of file renames (using the .dlock extension) within a short window, alongside the creation of known ransomware notes (HOW_RECOVER*.txt or RECOVERY_CHAT*.html) or the modification of the desktop wallpaper registry key to point to a file in C:\ProgramData.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
6015
Detects a credential-phishing email linking to a spoofed Microsoft device-code login flow (deviceaddcredential.srf) from a sender/recipient domain mismatch, or delivery of the associated known malicious attachment hash.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
208
Detects the execution of LOLBins (PowerShell, mshta, cmd, wscript) directly spawned from common web browsers (explorer, chrome, edge, firefox) with command-line arguments indicative of malicious activity, such as base64-encoded commands, hidden window styles, or remote script download and execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
13025
This rule detects PowerShell processes (powershell.exe, powershell_ise.exe, pwsh.exe) that execute the 'Compress-Archive' cmdlet in conjunction with strings indicative of data staging or exfiltration workflows (e.g., 'ZIPDOWNLOAD', '-DestinationPath'). The detection logic further narrows the scope by identifying if the parent process (InitiatingProcessCommandLine) involved activities related to downloading or uploading files, suggesting an automated staging and potential exfiltration sequence often seen in malicious backdoors.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
4015
The following analytic detects modification of the PYTHONPATH environment variable in conjunction with a package installation process.
Python looks up the `sys.path` variable, which is generated by combining user and site folders with `.pth` files and the value of the PYTHONPATH environment variable, to determine which directories to use for importing modules.
If an adversary is able to control the value of PYTHONPATH, they can point it to an attacker-controlled directory and hijack imported packages, achieving user-level persistence across future Python invocations and new shell sessions.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked by the affected user.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
001
KQL Query
avatar
Subash Ghimire@iamsubashg
avatar
Detections.ai Community
2 months ago
208
Detects command-line execution patterns involving the instantiation of potentially malicious COM objects (such as ADODB.Stream, Shell.Application, or network-related objects) using WScript.CreateObject or ActiveXObject. This pattern is commonly used in malicious JScript/VBScript to facilitate file operations, command execution, or network communication.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
000
This rule detects mass disabling of Windows Event Log channels by monitoring registry value modifications where multiple 'Enabled' values are set to '0' within a short timeframe. This behavior is indicative of anti-forensics activity where an adversary attempts to suppress specific log sources to evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
3017
Detects a Zoom client (zoom.exe/CptHost.exe) crashing or spawning an unexpected non-Zoom child process with an access-violation/stack-corruption/heap-overflow signature within 10 seconds of annotation-channel network activity, indicating attempted or successful exploitation of the ZOOMSDAY zero-click annotation RCE (CVE-2026-53413). Excludes known Zoom updater, crash-reporter, and screen-share helper processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects access-token duplication combined with CreateProcessAsUserA spawning the non-standard synchost.exe process outside System32 under a target interactive session.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
007
Detects Microsoft Defender exclusions added via wmic/MSFT_MpPreference for a fake Windows Defender installation directory used to shelter CoolClient components.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
507
This rule detects potentially malicious command execution (RCE) originating from AI orchestration platforms and development runtimes (such as Ollama, LangChain, AutoGen, CrewAI, n8n, Node.js, and Python). It flags instances where these processes spawn command shells (cmd.exe, powershell.exe, bash, sh) and execute suspicious command-line patterns indicative of code injection or command execution (e.g., eval(), exec(), subprocess, child_process). The rule uses a threshold of 3 or more occurrences in a 15-minute window per device and process to reduce noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
8010
Detects execution of processes that reference suspicious Windows API functions related to token manipulation or process injection, specifically when initiated by critical system processes like svchost.exe or lsass.exe. This activity often indicates attempts at credential access or privilege escalation.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
6014
Static file-based detection of the ACRStealer dropper, encrypted AutoIt payload, and DCRCVDrv.sys BYOVD driver via filenames, service/device names, signer names, and certificate serial. Certificate/signer matches only fire in combination with the driver file or service artifacts to avoid flagging the legitimate vendor certificate alone.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
This rule detects the creation of potentially malicious web-accessible files (e.g., .aspx, .ashx, .asmx) within sensitive SharePoint directory paths by the w3wp.exe process. This behavior is indicative of a webshell upload, which is a common persistence mechanism used by adversaries after gaining access to a web server.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
14016
Detects HTTP POST requests characteristic of the Kynx Stealer's ChunkSender module. The rule monitors for specific URI patterns used during the exfiltration phase, where stolen data categories like passwords, cookies, and system information are sent to a remote C2 panel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
009
Page 466 of 1866