Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects executables launched by common LOLBins (msiexec, powershell, cmd, wscript, cscript, regsvr32, rundll32)
that are either signed by a non-Microsoft/non-trusted-third-party publisher, or entirely unsigned.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
205
The following analytic detects non-Firefox processes accessing the Firefox profile directory, which contains sensitive user data such as login credentials, browsing history, and cookies. It leverages Windows Security Event logs, specifically event code 4663, to monitor access attempts. This activity is significant because it may indicate attempts by malware, such as RATs or trojans, to harvest user information. If confirmed malicious, this behavior could lead to data exfiltration, unauthorized access to user accounts, and further compromise of the affected system.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
000
This rule detects scenarios where a new user account is created (Event ID 4720) and is subsequently logged into (Event ID 4624) within a 30-minute window. This behavior can indicate an adversary creating a backdoor or service account for persistence or lateral movement, followed by immediate usage of that account.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
1017
This rule detects network connections from common administrative processes (such as PowerShell, CMD, WScript, or Rundll32) to known dynamic DNS providers. This pattern is frequently indicative of malware beacons, command and control (C2) communication, or other unauthorized remote access tools utilizing dynamic DNS services to maintain connectivity to adversary infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
1027
Detects run.pyw wrapper scripts embedding RC4-encrypted RAT blob with key-schedule byte pattern and ChaCha20 decryption routine with constant signature, for EtherHiding C2 config, used by DeviceManager RAT
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects the DeviceManager RAT (run.pyw, spawned via python.exe/pythonw.exe) launching PowerShell or cmd with encoded/obfuscated arguments (-enc, -EncodedCommand, -e, -nop, -w hidden), consistent with C2-tasked arbitrary command execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
This rule detects when Microsoft Defender SmartScreen identifies and blocks or warns users about access to known 'ClickFix' phishing landing pages. These pages often attempt to social engineer users into executing malicious commands via copy-paste actions (e.g., in a terminal or Run dialog) as a deceptive remediation step for fake browser errors.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5018
This rule identifies non-Microsoft processes (based on file name, file company name, and process signer) that initiate network connections to known Microsoft authentication endpoints. This behavior is often indicative of an adversary-controlled process attempting to leverage cloud services or perform authentication-related activities outside of expected system or productivity software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
7328
Detects certutil.exe -urlcache usage or PowerShell Invoke-WebRequest retrieving main.exe/cryptor.exe or similarly named payloads, followed by execution of the downloaded file, excluding downloads from an allowlist of approved internal software-distribution domains.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
This rule detects the use of native Windows utilities 'vssadmin.exe' and 'wmic.exe' to delete Volume Shadow Copies. This activity is a common tactic used by ransomware and other malicious actors to prevent system recovery by destroying backups, and is classified as Inhibit System Recovery.
avatar
Christopher Scott@Scocha
avatar
Detections.ai Community
2 months ago
4011
This rule detects the use of the 'bcdedit.exe' utility to modify Windows Boot Configuration Data (BCD) settings to disable system recovery features, such as boot recovery or automatic failure handling. Such actions are commonly performed by ransomware or other destructive malware to prevent system restoration after encryption or data damage.
avatar
Christopher Scott@Scocha
avatar
Detections.ai Community
2 months ago
5011
Correlates DNS TXT-tunneling activity and HTTP POST traffic from the same host resolving to the same base destination domain within a 2-minute window, with minimum volume thresholds on each channel, consistent with malware that branches between DNS tunneling and HTTP POST C2 modes based on the first byte of a decrypted configuration string.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
24145
This rule detects potential multi-stage desktop takeover attacks by monitoring sequences of process execution within a 5-minute window. It looks for initial shell (explorer.exe or cmd.exe) spawning script-based tools (mshta.exe, wscript.exe, cscript.exe, powershell.exe, cmd.exe) with suspicious command-line arguments (extensions like .lnk, .url, .hta, or PowerShell-specific artifacts like 'IEX', 'DownloadString', or '-enc'). This is immediately followed by a secondary stage where PowerShell, cmd, or rundll32 are used to load external DLLs, register modules via regsvr32, or interact with AppData/Local/Temp directories, indicative of payload staging and execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
003
This rule detects potential adversary activity aimed at disabling security tools, critical infrastructure services, or cloud synchronization agents. It monitors for a high volume (6 or more) of process termination commands (e.g., taskkill, net stop) or registry-based service disabling (Start value 4) targeting a predefined list of security and critical system services within a 3-minute window, which is indicative of an attempt to blind security monitoring or disrupt system availability.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
005
This rule detects mass disabling of Windows Event Log channels by monitoring registry value modifications where multiple 'Enabled' values are set to '0' within a short timeframe. This behavior is indicative of anti-forensics activity where an adversary attempts to suppress specific log sources to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
415
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
405
Detects a security-software presence check (360 Total Security/eScan process names) followed within 10 minutes by a persistence-establishing event from the same parent process.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects registration/activity of the msagent.sys filesystem minifilter driver used to deny access to and hide CoolClient-protected files and directories.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
102
Detects DLL sideloading where a renamed Sangfor executable (defender.exe/Sang.exe) loads libngs.dll/libsrapc.dll outside the legitimate install path or with a signer mismatch.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects modification of the CoolClient rootkit's stealth-configuration registry value (Wid_H1deF5Dirs) under the \SYSTEM\RNG hive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects CoolClient's elevated self-relaunch using the 'passuac' command-line parameter combined with RPC-based process creation and PPID spoofing to bypass UAC.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
202
Page 475 of 1866