Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects anomalous, non-browser process activity interacting with Microsoft Teams APIs associated with the TWINLOOT threat campaign. The rules identify suspicious token retrieval requests and unauthorized authentication headers from processes that do not identify as legitimate browser or Teams application agents, indicating potential abuse of application access tokens and authentication flows.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
The following analytic detects a Windows Defender malware detection or remediation event where the scanned path resolves through the NT object manager namespace (\globalroot\).
It leverages Windows Defender Operational log EventCodes 1116 and 1117 to identify this activity.
In the ShieldBreak exploit, this is how Defender is coerced into hydrating a cloud file placeholder and copying attacker content through a symbolic link chain that ultimately writes into C:\Windows\System32.
If confirmed malicious, this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
001
Detects registry modification/deletion attempts blocked with STATUS_ACCESS_DENIED on hosts running msagent.sys, restricted to msagent/RNG-related key paths.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects execution of the typosquatted process synchost.exe (distinct from the legitimate svchost.exe) when unsigned or running outside System32.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
This rule detects potential webshell activity by monitoring the correlation between web server processes spawning suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe) and the creation of executable or script files within identified web directories. The logic establishes a high-confidence correlation when both events occur on the same device within a 15-minute window, while also surfacing uncorrelated individual process spawns or suspicious file writes as lower-confidence indicators. It includes exclusions for known administrative and deployment processes to reduce noise.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
6012
Detects SilentDataCollector host-based surveillance: recurring screenshot capture, keylogging, WhatsApp Web automation, or known stealer binary execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
This rule detects potentially unauthorized command-line activity originating from Power Platform-related execution environments (such as Copilot Studio or Power Platform sandboxes). It specifically monitors for the execution of common system administration binaries like cmd, powershell, or curl, which, when triggered from within a low-code/cloud runtime environment, may indicate a sandbox escape or an attempt to interact with the underlying host operating system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
308
Detects instances where AI coding assistants (e.g., Cursor, Claude, Copilot) are observed interacting with specific configuration or sensitive files and subsequently initiating suspicious shell commands. The rule correlates file read activity (containing keywords like 'skill', 'preflight', '.ssh', or '.aws') followed closely by execution of potentially malicious commands like 'whoami /priv', credential decoding, or registry exploration, indicating potential abuse of the assistant's context.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
5113
Detects high-risk or uncategorized events involving the 'Isolate' action or Remote Browser Isolation (RBI) as logged by Microsoft Defender for Endpoint.
avatar
KQL Cowboy@KQLCowboy
avatar
Netskope Detection Engineering
2 months ago
102
Detects anomalous, frequent, or repetitive device crash events (including BSODs) on a single device, which may indicate system instability, hardware failure, or an attempt to induce a Denial of Service (DoS) condition on the endpoint.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
002
Detects devices exhibiting sustained high CPU or memory utilization (>= 90%) for a duration of at least 30 minutes, which may indicate resource exhaustion, performance degradation, or potentially malicious activity such as cryptocurrency mining, denial-of-service, or other unauthorized resource-intensive processes.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
002
Detects BumbleBee loader binaries that utilize the GetSystemDefaultLocaleName API to perform geofencing, intentionally exiting if the system locale matches specific CIS (Commonwealth of Independent States) region strings. This behavior is used by the malware to avoid infection of systems in these regions.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
002
This rule detects the suspicious execution of the psql.exe command-line client interacting with the Veeam Backup database. It specifically monitors for attempts to query database tables containing sensitive user_name and password information, often correlated with WMI or encoded PowerShell execution, which suggests an attempt to extract credentials from backup software.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
102
Detects high-risk or uncategorized events involving the 'Isolate' action or Remote Browser Isolation (RBI) as logged by Microsoft Defender for Endpoint.
avatar
KQL Cowboy@KQLCowboy
avatar
Detections.ai Community
2 months ago
002
Detects command-line activity indicative of attempts to disable, bypass, uninstall, or interfere with the Netskope security agent functionality on an endpoint.
avatar
KQL Cowboy@KQLCowboy
avatar
Detections.ai Community
2 months ago
002
Suricata signature chain detecting a burst of 20+ 592-byte ExtChild AddObj annotation messages from a single source within 5 seconds (heap-spray pattern), followed by a RemoveObj/ModifyObj teardown operation consistent with dispatch through a corrupted vtable pointer — the full CVE-2026-53414 heap overflow and control-flow hijack chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Suricata signature for a Zoom annotation PDU carrying opcode 0x10001 (AddObj) delivered on the downstream acknowledgement channel (which should only carry 0x10002/AddObjAck), indicating sender-role/opcode confusion that lets any participant forge presenter-privileged annotation objects (ZOOMSDAY, CVE-2026-53413/53414/53415).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Correlates end-to-end encryption (E2EE) enablement events with either an absence of expected server-side annotation-filter log entries or a malformed annotation payload indicator (CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange/CAnnoExtBlock/CAnnoPduAddObj fields) within the same 15-minute window, surfacing meetings where Zoom's server-side ZOOMSDAY mitigation could not inspect traffic.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects a Zoom client (zoom.exe/zoom.us/CptHost.exe) terminating abnormally (SIGABRT/SIGSEGV/stack corruption) from within the annotation module (libannotate.so) within 30 seconds of receiving a message-type-75 (CAnnoObjAutoMetaShape) annotation object, indicating exploitation of the linked-list unlink write-what-where primitive (CVE-2026-53415). Excludes update-triggered restarts and graceful shutdowns.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects presence of the EICAR AV test file only when co-occurring with ShieldBreak exploit artifacts (PoC binary, build files, or Warden.dll) in the same directory or process context, indicating exploit development/testing activity rather than routine AV testing.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5010
Detects network access to known repositories hosting the publicly disclosed ShieldBreak Microsoft Defender zero-day bypass PoC/tooling (GitHub, Project Nightcrawler, Church of Malware mirrors) via HTTP host/URI or TLS SNI matching.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1010
Page 468 of 1866