Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects JWR phishing kit's fake loading progress-bar overlay (p-bar/_pbar with a maximal z-index) used to mask the hidden iframe's C2 negotiation while building victim trust.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects the JWR phishing kit's JwrControlInstruction mechanism relaying operator commands to the victim browser across branded login, OTP/2FA capture, and card-retry page flows.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects the execution of Python or Pythonw processes with command-line arguments that include base64 decoding followed by the exec() function. This pattern is commonly used by adversaries to execute obfuscated or encoded malicious code directly in memory to evade detection.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
3019
Detects installation or execution of AnyDesk, Google Remote Desktop, or MobaXterm from user-writable directories (Downloads, Temp, AppData) outside the approved software baseline, excluding code-signed installs pushed via Intune/SCCM.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3014
Potential exploitation of JetBrains TeamCity (Unauthenticated RCE, CVE-2026-63077) looking for suspicious child processes spawned by TeamCity services.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
409
This rule detects sequences of suspicious process activity where multiple known LOLBins (Living Off the Land Binaries) execute in a chain. Specifically, it monitors for scenarios where a process from a predefined list (e.g., msdt.exe, mmc.exe, rundll32.exe) initiates another process from the same list, often indicative of proxy execution or privilege escalation techniques involving suspicious command-line parameters like '-embedding', 'NtLoadDriver', or '/i:'.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
107
Detects PlugX-style initial-foothold staging: process injection followed within minutes by a dropped file that is then executed, excluding known-benign AV/EDR/updater injectors and targets.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects msagent.sys driver load correlated with subsequent protection (reduced handle access rights) of an unsigned, non-standard synchost.exe process within a 1-hour window.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects DKOM-style kernel process hiding: processes created but never appearing in periodic enumeration snapshots across multiple consecutive polls.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
This rule detects the use of double extensions in file names to masquerade executable files as benign document or media file types (e.g., 'document.pdf.exe'). This is a common technique used by attackers to trick users into executing malicious files by hiding their true extension.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
3010
Detects the msagent.sys signed kernel-mode rootkit driver used by the CoolClient backdoor (HoneyMyte/Mustang Panda)
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects network retrieval of the ShieldBreak exploit PoC or the UnDefend companion tool from their known distribution infrastructure (git.projectnightcrawler.dev, github.com/Nightmare-Eclipse/UnDefend) via TLS SNI or HTTP host/URI matching.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
109
This analytic detects uncommon processes reading or requesting read access to sensitive files from cloud providers on Windows endpoints.
It monitors Windows Security Event 4663 for ReadData (AccessMask 0x1) operations against sensitive files from cloud providers such as Azure.
Access by any process outside the known toolchain may indicate credential theft or cloud identity reconnaissance activity, including infostealer behavior such as one observed in Vidar Stealer variants.
This detection currently only supports Azure sensitive files, but will be extended to support other cloud providers in the future.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
001
The following analytic detects suspicious remote thread execution in processes such as Taskmgr.exe, calc.exe, and notepad.exe, which may indicate process injection by malware like Qakbot. This detection leverages Sysmon EventCode 8 to identify remote thread creation in specific target processes. This activity is significant as it often signifies an attempt by malware to inject malicious code into legitimate processes, potentially leading to unauthorized code execution. If confirmed malicious, this could allow attackers to execute arbitrary code, escalate privileges, or maintain persistence on the compromised host.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
001
The following analytic detects an access request on the uninstall registry key. It leverages Windows Security Event logs, specifically event code 4663. This activity is significant because adversaries or malware can exploit this key to gather information about installed applications, aiding in further attacks. If confirmed malicious, this behavior could allow attackers to map out installed software, potentially identifying vulnerabilities or software to exploit, leading to further system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
001
This rule detects modifications to BitLocker registry keys associated with encryption settings, such as enabling/disabling device encryption or modifying startup requirements. These actions could be used by an adversary to weaken, bypass, or disable full-disk encryption to facilitate data theft or gain persistent access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
907
This rule detects high volumes of network traffic originating from processes other than common web browsers (chrome, msedge, firefox) to specific edge computing and logging infrastructure (ingest.sentry.io, workers.dev, pages.dev). This behavior is indicative of non-browser processes, potentially malicious implants or scripts, using legitimate cloud-based edge services as command-and-control (C2) infrastructure or for data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
517
This rule identifies network connections using deprecated, insecure TLS versions (TLS 1.0, 1.1) or weak cipher suites (RC4, 3DES, NULL). The use of these legacy cryptographic protocols is a security risk, as they are vulnerable to various attacks like man-in-the-middle, and may indicate misconfigured servers, legacy infrastructure, or attempts by an adversary to downgrade encryption to facilitate traffic interception or inspection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
307
Detects DLL sideloading of a malicious, AES-256-encrypted borlndmm.dll masquerading as an NVIDIA graphics library, loaded via the legitimate ACCA Software S.p.A.-signed ABRSubProcess.exe to launch OnyxC2.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
305
This rule detects attempts to disable, stop, or uninstall various security products, including antivirus and EDR solutions, by monitoring command-line activity for administrative utilities like sc.exe, net.exe, wmic.exe, and PowerShell.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
10215
Detects DLL side-loading of the unsigned tbbmalloc.dll by the signed binary pgocvt.exe from the C:\ProgramData\TIEmounter\ staging directory — a second-stage follow-on payload technique in the ACRStealer campaign.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Page 469 of 1866