Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution of potentially malicious processes originating from common mail client attachment cache directories, the use of suspicious double extensions in file names, or common command-line interpreters being spawned by Microsoft Office applications, which are high-confidence indicators of phishing or malicious document exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects ScreenConnect client processes initiating outbound network connections to external cloud relay addresses (typically *-relay.screenconnect.com) from locations outside of standard Program Files directories. This behavior is indicative of unauthorized, standalone, or adversary-deployed ScreenConnect instances attempting to establish a Command and Control (C2) channel, bypassing standard IT-managed deployment pathways.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects the deployment and activity of the MeshCentral remote management agent (meshagent), including process execution, service creation, and network communication to MeshCentral infrastructure. This behavior is indicative of unauthorized persistence and remote command-and-control, often associated with post-compromise activity such as that observed by ShinyHunters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects web requests targeting Oracle PeopleSoft Integration Broker (PSIGW) endpoints that contain suspicious query parameters associated with exploitation attempts, such as path traversal sequences, command injection patterns, or Java-based class invocations. This rule is designed to identify exploitation attempts against PeopleSoft systems as observed in the mid-2026 ShinyHunters zero-day campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the installation or first execution of common remote monitoring and management (RMM) software, specifically AnyDesk, TeamViewer, or ScreenConnect, shortly after an identity change or MFA reset event, indicative of social engineering vishing-to-remote-access techniques often employed by threat actors such as Scattered Spider (UNC3944).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects potential NTLM relay attacks targeting Active Directory Certificate Services (AD CS) web enrollment endpoints, including subsequent certificate requests for sensitive templates. This pattern identifies attackers attempting to relay NTLM authentication to AD CS and potentially requesting certificates for high-privilege templates (e.g., DomainController, SubCA, Machine, or User) to facilitate privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
101
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
101
Detects anomalous or potentially malicious LDAP queries on Domain Controllers, utilizing Event ID 1644 to monitor query filters. The rule identifies patterns commonly associated with reconnaissance and enumeration activities, including Kerberoasting (SPN enumeration), AS-REP roasting, delegation abuse, Active Directory Certificate Services (AD CS) enumeration, BloodHound collection, and bulk user, group, or computer discovery.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
14 days ago
105
Page 51 of 1870