Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the execution of LOLBins (PowerShell, mshta, cmd, wscript) directly spawned from common web browsers (explorer, chrome, edge, firefox) with command-line arguments indicative of malicious activity, such as base64-encoded commands, hidden window styles, or remote script download and execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
9111
This rule extracts and audits inventory information from local agents, including vendor, device name, account context, and associated process information. It is designed to provide visibility into the state and configuration of installed local agents within the environment.
avatar
Goksel Atakan@gokselatakan
Defender - KQL
2 months ago
7012
Detects the addition of new domain accounts using the 'net group /add /domain' command. This activity can be indicative of an adversary establishing persistence or escalating privileges within a domain environment.
avatar
Barsha Sketh@Barshasketh
avatar
Detections.ai Community
2 months ago
205
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
508
This rule monitors for successful GlobalProtect gateway connections from users who have not successfully connected in the preceding 30 days, specifically identifying users connecting with a client fingerprint of 'Microsoft Windows 10 Pro 64-bit'. This behavior is indicative of potential initial access using compromised or new credentials, or specifically flagging suspicious activity patterns associated with specific exploit proof-of-concept client fingerprints.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
008
Detects high-frequency state changes in authentication events for a single account within a short time window. This type of 'flapping' behavior, where an account repeatedly toggles between different authentication statuses (e.g., success and failure) on one or more hosts, can be an indicator of brute force attempts, credential stuffing, or misconfigured automated authentication services.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
001
This rule monitors process execution events and correlates them against a watchlist of known malicious or suspicious binary names, such as crypto-miners, unauthorized remote access tools, or renamed system utilities (LOLBins) being executed from suspicious locations.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
001
This rule detects potentially unauthorized command-line activity originating from Power Platform-related execution environments (such as Copilot Studio or Power Platform sandboxes). It specifically monitors for the execution of common system administration binaries like cmd, powershell, or curl, which, when triggered from within a low-code/cloud runtime environment, may indicate a sandbox escape or an attempt to interact with the underlying host operating system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
505
This rule detects potentially malicious attempts to modify Windows process protection levels, often used by attackers employing Bring Your Own Vulnerable Driver (BYOVD) techniques. It identifies when processes use command-line arguments like 'PsProtectedSignerAntimalware' or 'SetProcessMitigationPolicy' to assign elevated protection levels, while simultaneously ensuring the initiating process is either unsigned or not a standard executable file, which is highly indicative of suspicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
505
This rule detects sequences of suspicious process activity where multiple known LOLBins (Living Off the Land Binaries) execute in a chain. Specifically, it monitors for scenarios where a process from a predefined list (e.g., msdt.exe, mmc.exe, rundll32.exe) initiates another process from the same list, often indicative of proxy execution or privilege escalation techniques involving suspicious command-line parameters like '-embedding', 'NtLoadDriver', or '/i:'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
505
This rule monitors process execution events and correlates them against a watchlist of known malicious or suspicious binary names, such as crypto-miners, unauthorized remote access tools, or renamed system utilities (LOLBins) being executed from suspicious locations.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
001
This rule detects suspicious execution patterns of addinutil.exe, a legitimate .NET utility that can be abused for arbitrary code execution. It specifically looks for two conditions: 1) addinutil.exe being executed from its standard .NET Framework directories with the '-AddinRoot .' argument, which is a known LOLBAS technique to load a payload from the current directory, and 2) addinutil.exe being executed from an uncommon or non-standard directory, which could indicate an adversary has copied the utility to a different location for malicious purposes.
avatar
KQL Cowboy@KQLCowboy
avatar
Detections.ai Community
2 months ago
001
Detects suspicious command-line activity originating from TeamCity service processes on Windows. The rule looks for unexpected child processes (e.g., cmd.exe, powershell.exe, curl.exe) initiated by the TeamCity server or associated Java processes, which may indicate exploitation of an unauthenticated remote code execution vulnerability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects bulk file copy to staging directories, mass file read access, mailbox-export-rule creation, and bulk PST/mailbox access, excluding DLP/eDiscovery/legal-hold exports tagged with a case ID and scheduled data-migration windows.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
109
Detects OpenSSH installation on Windows hosts, unexpected internal SSH sessions, and SSH tunnels terminating at an external (non-RFC1918) destination — particularly from SSL-VPN admin hosts — excluding documented DevOps CI/CD runners and known bastion hosts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
409
A GitHub maintainer account related to the keyv/cacheable npm package ecosystem was compromised. The attacker published malicious versions of these packages, which affected more than 400 npm packages. The malware is designed to steal cloud credentials, developer secrets, CI/CD secrets, AI tool configuration files, and cryptocurrency wallet data. It also creates persistence using Claude Code hooks and VS Code tasks.json files, and sends stolen data to attacker-controlled GitHub repositories and C2 domains.

Reference article: https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
avatar
Kumaresan Selladurai@KumaresanSelladurai
avatar
Detections.ai Community
2 months ago
59055
Detects execution of whoami.exe as NT AUTHORITY\SYSTEM within a short window of, and parented by, a suspicious SYSTEM-privileged shell spawn — a common post-exploitation confirmation step following successful ShieldBreak exploitation. Standalone whoami execution is excluded by design.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
206
This rule detects the execution of known Remote Monitoring and Management (RMM) or remote access tools on devices where they have not been observed within the previous 90-day baseline (excluding the most recent 7 days). This pattern is often indicative of an adversary introducing unauthorized remote access capabilities for persistence or lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
10010
KQL Query
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
17070
Detects potential data exfiltration attempts using PowerShell by identifying Invoke-WebRequest usage with specific flags (Put, ContentType, InFile) or encoding patterns (EncodedCommand) while targeting sensitive file extensions, directories, or suspicious network destinations.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
26068
Detects the full technical staging sequence unique to the ShieldBreak CLFS time-of-check-to-time-of-use (TOCTOU) technique: cloud provider registration, WD_TARGET/WD_SHADOW object-manager directory creation, WD_SCAN object-link creation under the normal and CLFS namespaces, ntdll.dll copy into a BERLIN alternate data stream, the link-deletion/CLFS-log-lock race sequence, and the final phoneinfo.dll:stream lock confirming the file-overwrite primitive succeeded.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
406
Page 473 of 1866