Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule detects the loading of a driver by system utilities (drvinst.exe, pnputil.exe, setupapi.dll, or System process) shortly after a PnP (Plug and Play) device connection event. It specifically flags instances where the driver file is located in suspicious directories (Windows/Temp, Users/Public, AppData/Local/Temp) or the file does not have a .sys extension, which are common indicators of malicious driver installation or BYOVD (Bring Your Own Vulnerable Driver) tactics.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
406
Detects installation of the 'media_updaten' Windows service configured to run Sang.exe with the 'work' argument, used by CoolClient for persistence.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
Detects scheduled-task persistence launching masqueraded defender.exe/Sang.exe with SYSTEM privileges at startup, outside legitimate Windows Defender/Sangfor install paths.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
This rule detects potentially malicious PowerShell activity characterized by the co-occurrence of file download indicators (such as Invoke-WebRequest, WebClient, or UserAgent strings) and file execution or staging commands (such as IEX, Expand-Archive, or Copy-Item) within the same command line. It is designed to identify ingress tool transfer and command-line execution patterns often associated with post-exploitation or malware staging, while reducing noise by requiring both download and operational intent.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
508
This rule detects processes initiating network connections to standard POP3 (110, 995) and IMAP (143, 993) ports that are not identified as trusted, well-known mail clients. By filtering out connections from common email application paths and local IP ranges, it aims to identify potentially malicious processes, scripts, or non-standard tools attempting to perform email collection or exfiltration directly from mail servers.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
208
This rule detects the use of the Windows certutil.exe utility with flags commonly abused by adversaries for file downloads (-urlcache, -urlfetch) or file deobfuscation/decoding (-decode, -decodehex, -encode). It specifically targets LOLBIN (Living Off the Land Binary) behavior by monitoring process command line arguments, while providing allowances for common administrative tasks like PKI maintenance or CRL/OCSP updates to minimize false positives.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
708
Detects Defender XDR alerts and evidence potentially related to Certighost / CVE-2026-54121 AD CS abuse, including suspicious certificate requests, Kerberos activity, LDAP security principal anomalies, and possible DCSync or directory replication abuse.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
9032
This rule detects suspicious activity originating from an Internet Information Services (IIS) worker process (w3wp.exe) associated with Microsoft SharePoint. It monitors for the spawning of common command-line shells, interpreters, or Living-off-the-Land Binaries (LOLBins) from the SharePoint IIS worker process, which is a potential indicator of Remote Code Execution (RCE) exploitation, specifically targeting vulnerabilities like the hypothetical CVE-2026-45659.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
509
This rule detects the creation of potentially malicious web-accessible files (e.g., .aspx, .ashx, .asmx) within sensitive SharePoint directory paths by the w3wp.exe process. This behavior is indicative of a webshell upload, which is a common persistence mechanism used by adversaries after gaining access to a web server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
929
Detects unusually large 7-Zip/WinRAR archive creation from non-standard staging directories followed by outbound network activity, consistent with Gunra's data-staging step before double-extortion exfiltration.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
8011
Detects registry key/value creation, modification, or deletion by the unsigned OnyxC2 dropper process (Setup_File_92.118.3096.exe) running from a Temp\Rar or Downloads path, consistent with OnyxC2 configuration/persistence storage.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
204
Detects LSASS memory access via PROCESS_VM_READ combined with MiniDumpWriteDump-style API usage from an unsigned or untrusted process, correlated with a nearby dump-file creation, consistent with OnyxC2's premium-tier credential dumping.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
204
Detects HTTP requests to the OnyxC2 backend API sync endpoint (akmuniverstall.top) carrying the characteristic hwid, ownertoken, and botversion=3.0 parameters used for device-fingerprint C2 check-ins.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects a low-level keyboard hook or screen-capture API call from an unsigned, non-standard-path process, correlated with periodic image/keystroke buffer file staging, consistent with OnyxC2's premium keylogger/screenshot module.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
204
Correlates the ShieldBreak PoC's 'Exploit succeeded' console output with a SYSTEM-privileged cmd.exe spawn in the same process session within a short window, confirming successful end-to-end exploitation of CVE-2026-50656.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects JWR phishing framework client engine script via known SHA256 hashes (standalone high-confidence), or the co-occurrence of anti-debug check, staging path structure, and Simplified Chinese operator status strings
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Correlates DNS/network requests to newly observed domains matching JWR's brand-plus-suffix generation pattern across .top/.cfd/.info/.cc TLDs, requiring multiple distinct hostnames sharing the same brand token within a short window to flag likely batch-registered phishing infrastructure.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects the hard-coded RC4 key fragment used by BTR.sys to decrypt its transaction structure when co-located within 0x4000 bytes of the FEE1DEAD magic value and Version 2 header field, targeting the encrypted transaction/ADS payload content independent of driver binary version.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
100
Detects suspicious Active Directory Replication Service (ADRS) requests originating from
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.

Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 months ago
20061
Detects additions to privileged groups (e.g. Domain Admins) or modification of password-change-policy flags on a previously dormant account being reactivated, excluding changes linked to an approved change-management ticket and weighting more heavily for off-hours or non-standard admin workstation origin.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6010
Detects creation of a scheduled task named 'IntelSoftwareUpdater' via schtasks.exe that launches pythonw.exe with run.pyw, used by the UNC5142 DeviceManager RAT for persistence, relaunching every 10 minutes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Page 471 of 1866