Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,173 detections

Detects the hard-coded RC4 key fragment used by BTR.sys to decrypt its transaction structure when co-located within 0x4000 bytes of the FEE1DEAD magic value and Version 2 header field, targeting the encrypted transaction/ADS payload content independent of driver binary version.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
100
Detects suspicious Active Directory Replication Service (ADRS) requests originating from
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.

Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 months ago
20061
Detects additions to privileged groups (e.g. Domain Admins) or modification of password-change-policy flags on a previously dormant account being reactivated, excluding changes linked to an approved change-management ticket and weighting more heavily for off-hours or non-standard admin workstation origin.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6010
Detects creation of a scheduled task named 'IntelSoftwareUpdater' via schtasks.exe that launches pythonw.exe with run.pyw, used by the UNC5142 DeviceManager RAT for persistence, relaunching every 10 minutes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects TLS sessions to Sapphire Sleet/UNC1069 Hostwinds C2 infrastructure presenting the exact self-signed certificate issuer string linked to the Mastra/axios campaigns.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000
This rule detects network communication attempts (connection success, request, or failure, or any traffic on port 443) targeting a specific malicious domain (notepadreleased.com) or IP address (85.158.110.78), while explicitly excluding common public DNS providers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
407
Detects a non-system process causing creation of CldFlt0.etl under C:\Windows\System32\LogFiles\CloudFiles\.
This path is initialised by the CldFlt driver when a process calls CfRegisterSyncRoot() or CfConnectSyncRoot().
In the RedSun exploit this is a side-effect of the DoCloudStuff() function that registers a fake sync provider to create the cloud-tagged bait file.
Legitimate cloud providers (OneDrive etc.) register sync roots from SYSTEM-level service processes, not from user-context executables.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
001
This rule detects potentially malicious attempts to modify Windows process protection levels, often used by attackers employing Bring Your Own Vulnerable Driver (BYOVD) techniques. It identifies when processes use command-line arguments like 'PsProtectedSignerAntimalware' or 'SetProcessMitigationPolicy' to assign elevated protection levels, while simultaneously ensuring the initiating process is either unsigned or not a standard executable file, which is highly indicative of suspicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
305
This rule detects command-line activity that references sensitive Windows API functions or privileges associated with token manipulation and process privilege escalation, such as SeDebugPrivilege, SeImpersonatePrivilege, DuplicateTokenEx, CreateProcessWithTokenW, and NtSetInformationToken. The rule excludes common service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to focus on potentially unauthorized use by standard or administrative accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
105
This rule monitors for two critical firmware-related conditions: detected non-compliance with secure boot, UEFI, or TPM configuration standards via Microsoft Defender TVM, and explicit firmware or boot configuration change events reported by device telemetry. It is designed to identify potential tampering or misconfigurations that could facilitate bootkits or other pre-OS persistence mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
105
This rule identifies network connections using deprecated, insecure TLS versions (TLS 1.0, 1.1) or weak cipher suites (RC4, 3DES, NULL). The use of these legacy cryptographic protocols is a security risk, as they are vulnerable to various attacks like man-in-the-middle, and may indicate misconfigured servers, legacy infrastructure, or attempts by an adversary to downgrade encryption to facilitate traffic interception or inspection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
205
Detects the installation of a Manifest V3 browser extension that requests the 'chrome.proxy' permission as its sole permission. This behavior is indicative of potential malicious extensions designed to modify web traffic or route browser activity through an adversary-controlled proxy server.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
305
This rule detects attempts to disable, stop, or uninstall various security products, including antivirus and EDR solutions, by monitoring command-line activity for administrative utilities like sc.exe, net.exe, wmic.exe, and PowerShell.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
7011
This rule detects scenarios where a new user account is created (Event ID 4720) and is subsequently logged into (Event ID 4624) within a 30-minute window. This behavior can indicate an adversary creating a backdoor or service account for persistence or lateral movement, followed by immediate usage of that account.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
9011
Detects execution of the SimpleChatProxy/'Chat Proxy' tool correlated with outbound traffic to an attacker-hosted image endpoint, used for operator-victim messaging and remote screenshot retrieval.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects an unsigned Loader.exe spawning a second unsigned executable that performs immediate outbound network fetch, matching the StopAndProtect loader/downloader chain with sandbox-evasion checks.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects the execution of LOLBins (PowerShell, mshta, cmd, wscript) directly spawned from common web browsers (explorer, chrome, edge, firefox) with command-line arguments indicative of malicious activity, such as base64-encoded commands, hidden window styles, or remote script download and execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
9111
This rule extracts and audits inventory information from local agents, including vendor, device name, account context, and associated process information. It is designed to provide visibility into the state and configuration of installed local agents within the environment.
avatar
Goksel Atakan@gokselatakan
Defender - KQL
2 months ago
7012
Detects the addition of new domain accounts using the 'net group /add /domain' command. This activity can be indicative of an adversary establishing persistence or escalating privileges within a domain environment.
avatar
Barsha Sketh@Barshasketh
avatar
Detections.ai Community
2 months ago
205
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
508
This rule monitors for successful GlobalProtect gateway connections from users who have not successfully connected in the preceding 30 days, specifically identifying users connecting with a client fingerprint of 'Microsoft Windows 10 Pro 64-bit'. This behavior is indicative of potential initial access using compromised or new credentials, or specifically flagging suspicious activity patterns associated with specific exploit proof-of-concept client fingerprints.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
008
Page 472 of 1866