Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution of Nova ransomware (formerly RALord) by monitoring for its specific modular command-line interface arguments, which include file encryption commands, ransom note deployment, and specific ransom note filenames. The rule monitors process creation events for strings like 'encrypt-all', 'encrypt-path', 'readme-add', '--workers', and the presence of the 'README_NOVA.me' ransom note or unique file extensions associated with its encryption activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
104
Detects execution of 'rnpkeys.exe' and associated DLLs ('rnp.dll' or 'tdwp.dll') located within the '\ProgramData\keyroll\' directory, which is a common persistence or staging location for malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
003
Detects AI agent tooling (e.g., Copilot, Cursor, Ollama) that makes outbound network calls to known AI model providers followed by the execution of suspicious shell commands within a short duration. The rule flags high-severity activities such as download-cradles, credential reconnaissance, LOLBin usage, and persistence mechanisms. Informational alerts are generated for standard CLI activity within the same timeframe.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
006
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
106
Detects the execution of known Python scripts (CES_Enroll.py, ntlm_ces_relay.py, ces_negotiate_ntlm.py) often associated with NTLM relay attacks or forced authentication techniques. These scripts leverage Python to interact with authentication protocols or relay requests.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
12 days ago
203
Detects credential-stuffing campaigns that employ AI/ML-tuned inter-request timing jitter to bypass traditional rate-limiting and fixed-interval bot detection, specifically flagging interactive or network logon failures on Windows hosts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
106
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
307
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
106
Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
004
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
004
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
205
This rule detects processes command lines containing specific strings ('EmbedHtml', 'EmbedHtml::GetUrl', 'GetUrl()') associated with suspicious NSIS (Nullsoft Scriptable Install System) script behavior often linked to the OpenSUpdater malware downloader, which uses these calls to fetch additional malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
This rule detects a single device making a high volume of connections to known machine learning model and dataset hosting repositories (e.g., Hugging Face, Kaggle, TensorFlow) within a short timeframe. Such activity may indicate bulk exfiltration of sensitive internal research data, proprietary models, or large datasets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
103
This rule detects the creation or presence of specific file artifacts ('PDF_C2089_20260911100446.exe' and 'active_desktop_render_x64.dll') within the '\AppData\Microsoft\Update\' directory. These file names and paths are characteristic of potential malware staging or persistence mechanisms, specifically associated with the SilverFox threat activity.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
101
This rule detects the presence of command line artifacts, filenames, and strings associated with the SilverFox malware. These strings indicate the execution of a malicious desktop monitoring component ('active_desktop_launcher.exe') or the use of specific IPC/configuration markers ('@@RAPID_CFG_START@@') characteristic of this threat's tradecraft.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
001
This rule detects executable files (ending in .exe) executing from a specific subdirectory within the user's AppData path (\AppData\Microsoft\Update\). This path is often used by adversaries to masquerade malicious activity or persistence mechanisms as legitimate update processes. The rule excludes common system service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise, focusing on processes initiated by user-level accounts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
101
Detects the specific pattern associated with Storm-2570 for enabling Remote Desktop Protocol (RDP) on a target host to facilitate lateral movement. The detection looks for registry modifications to disable RDP denial (fDenyTSConnections=0), firewall rules allowing TCP port 3389 via netsh or PowerShell, and the deployment of these configurations using PsExec against a target host list file.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
304
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001
Page 54 of 1870