Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,173 detections

Detects unauthorized modifications to the SAM registry hive (specifically keys and values related to user account RIDs) by non-system processes, which is a technique used in RID hijacking to grant elevated privileges or create hidden accounts.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
405
Detects the 12KB RtkNGUI64.exe backdoor built without a C runtime, using GCC (tdm64-1) 4.9.2 and custom CRC/table-based string obfuscation
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
302
Detects a fake desktop.ini file combining a legitimate-looking ShellClassInfo/LocalizedResourceName lure (shell32.dll,-21781) with a C2 domain hidden as unary-encoded trailing whitespace after byte offset 174 -- consolidates the lure-content and whitespace-encoding indicators into one high-fidelity rule
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects Cortex-managed endpoints that are currently in a disconnected state and are cross-referenced against an inventory of critical or sensitive assets. This rule highlights potential gaps in security monitoring and visibility for high-value systems.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
002
Detects execution of RClone from non-standard directories or outbound transfer to cloud endpoints outside an approved destination list, consistent with Gunra's pre-encryption data-exfiltration tooling.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4013
Detects Windows system binaries and commonly abused native LOLBins executing from outside their expected system directories, indicating a renamed, relocated, or imposter copy consistent with masquerading, DLL side-loading staging, or process-name spoofing.
avatar
Collin Lairamore@Bollinmore
avatar
Detections.ai Community
2 months ago
002
Detects Impacket-style (wmiexec, secretsdump, atexec, psexec.py, smbclient.py) and PsExec SMB admin-share lateral movement, excluding approved IT admin accounts and management servers.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5013
Detects RDP-based lateral movement, including pivots into VDI, AD, and authentication infrastructure, excluding known bastion/jump hosts and flagging sessions from atypical source workstations or off-hours timing.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5013
This rule detects the execution of 'cmd.exe' when it is spawned by a process that is not part of a common list of authorized parent processes. This behavior is often indicative of potential malicious activity, as adversaries may attempt to spawn shells from unexpected applications to maintain persistence, execute secondary payloads, or perform lateral movement.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
001
Detects the creation and configuration of a Windows service named 'media_updaten' via command-line utilities (sc.exe) or direct registry modification. This service is associated with CoolClient for persistence to relaunch 'Sang.exe' with a 'work' parameter.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
102
Detects remote process creation via wmic.exe/WmiPrvSE.exe and suspicious WMI event subscriptions, excluding known configuration-management platform service accounts (SCCM, Ansible, Puppet) and requiring the WMI connection to be the first-ever observed connection between the source/destination host pair.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6012
Detects file creation, write, or rename operations to specific paths known to be used in exploitation of CVE-2026-63077.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
408
This rule analyzes recent agent telemetry to identify and summarize the distribution of local agent vendors present in the environment over a 30-day lookback period. It extracts vendor information from agent metadata and provides a frequency count to assist in auditing deployed infrastructure agents.
avatar
Goksel Atakan@gokselatakan
Defender - KQL
2 months ago
7015
Detects the ShieldBreak Defender-scan TOCTOU exploit locking an alternate data stream on the protected system DLL phoneinfo.dll immediately prior to an arbitrary write — the core privilege-escalation primitive of CVE-2026-50656. Excludes legitimate Windows Update/servicing operations.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
408
This rule detects potentially malicious command execution (RCE) originating from AI orchestration platforms and development runtimes (such as Ollama, LangChain, AutoGen, CrewAI, n8n, Node.js, and Python). It flags instances where these processes spawn command shells (cmd.exe, powershell.exe, bash, sh) and execute suspicious command-line patterns indicative of code injection or command execution (e.g., eval(), exec(), subprocess, child_process). The rule uses a threshold of 3 or more occurrences in a 15-minute window per device and process to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
006
This rule detects high volumes of network traffic originating from processes other than common web browsers (chrome, msedge, firefox) to specific edge computing and logging infrastructure (ingest.sentry.io, workers.dev, pages.dev). This behavior is indicative of non-browser processes, potentially malicious implants or scripts, using legitimate cloud-based edge services as command-and-control (C2) infrastructure or for data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
106
This rule detects modifications to BitLocker registry keys associated with encryption settings, such as enabling/disabling device encryption or modifying startup requirements. These actions could be used by an adversary to weaken, bypass, or disable full-disk encryption to facilitate data theft or gain persistent access.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
106
Detects command-line activity indicating an attempt to extract generic passwords from Google Chrome or Brave browser credential storage, often associated with tools that access the 'Safe Storage' or similar password databases.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
6011
Detects deletion of Volume Shadow Copies and backup catalogs (vssadmin, wbadmin, wmic shadowcopy, bcdedit) consistent with Gunra ransomware's pre-encryption recovery-inhibition behavior, requiring correlated multi-command deletion sequences to reduce noise from routine backup retention.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2012
Detects OS credential dumping of the Active Directory NTDS.dit database via ntdsutil, VSS-based extraction, or Impacket's secretsdump.py, excluding approved AD backup jobs and accounts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5012
This rule detects potentially malicious activity leveraging the Windows Certutil utility for downloading, decoding, and executing files or payloads. It monitors process command line arguments to identify common download flags, hex/base64 decoding operations, evasion techniques, and interaction with high-risk file types or directories. The rule calculates a severity score based on the combination of these behaviors, such as downloading and decoding a file, or executing content from a temporary directory.
avatar
Christopher Scott@Scocha
avatar
Detections.ai Community
2 months ago
6022
Page 470 of 1866