Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
809
Detects a low-privileged account manually triggering the 'CreateObjectTask' scheduled task, which is a known technique to force the 'Shell Create Object Handler' (dllhost.exe) to start under the SYSTEM context. This behavior is often associated with pre-exploitation steps for privilege escalation vulnerabilities, specifically those involving OBJREF marshaling targeting specific COM objects.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
107
Detects the VelvetCake malware installation and operational pattern, which utilizes a scheduled task named 'OneDriveUpdateScheduler' to execute PowerShell scripts ('update1.ps1' or 'update2.ps1'). These scripts periodically retrieve modules or payloads from external infrastructure, specifically hardcoded C2 IPs or a dedicated GitHub repository.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
007
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
401
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
4012
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
101
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
101
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
101
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
101
Detects the use of reg.exe or PowerShell to modify the WSL InstallLocation registry key via command-line arguments.
Legitimate modifications to this key are performed exclusively by the Windows Installer (msiexec.exe) during WSL package installation or update.
Manual use of reg.exe or PowerShell to set this value strongly indicates an attempt to redirect WSL execution to a malicious binary.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
6 days ago
000
Detects anomalous behavior where a node.exe process establishes an outbound network connection, characteristic of a C2 registration or ping loop, followed shortly by the spawning of an interactive command shell (cmd.exe or powershell.exe) by the same node.exe process. This pattern is indicative of a RAT (Remote Access Trojan) shell handler execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
209
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
14 days ago
505
Detects a sequence of activity indicative of destructive ransomware or wiper behavior on a Windows device. The rule correlates a high volume of file modification, creation, or rename events within a short timeframe with concurrent attempts to delete or modify Windows backup and recovery mechanisms (such as Volume Shadow Copies or Boot Configuration Data) using native administrative utilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
202
Detects suspicious post-compromise activity associated with ALPHV/BlackCat affiliates. This rule monitors for anomalous Kerberos ticket requests (e.g., weak encryption types or TGS requests) closely followed by access to sensitive credential stores or tools on the same host, which is indicative of credential harvesting after a session hijacking or initial access event.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
202
Detects coordinated activity characteristic of NotPetya-like lateral movement. It identifies a local account authenticating across multiple hosts (credential reuse), followed by the creation of a transient Windows service (typically for remote command execution) and the invocation of rundll32.exe to execute a DLL export by ordinal on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
002
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
307
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
SlimKQL
17 days ago
6011
This rule detects file and process activity originating from or involving specific directories and filenames associated with 'Agta' software, including temporary files such as PowerShell scripts and XML tasks. This behavior is indicative of potential unauthorized use of backup or testing utilities for malicious purposes, such as script execution or task manipulation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
This rule identifies two distinct security threats on Windows systems: the execution or presence of files matching a known malicious SHA256 hash list, and modifications to the 'PromptOnSecureDesktop' registry key, which could indicate an attempt to weaken User Account Control (UAC) protections.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects modifications to the Windows registry key 'PromptOnSecureDesktop' to set it to '0' (disabled). This configuration change effectively disables the secure desktop for User Account Control (UAC) prompts, which is a technique used by adversaries to facilitate UAC bypasses or simplify credential harvesting by making UAC prompts more easily spoofable or interceptable.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
101
This rule monitors for processes masquerading as Dell-related software (e.g., 'Dell Window Guard.exe', 'Dell.Virus.Guard.exe') or processes containing the command-line argument 'AgtaBackstage'. It flags devices where multiple variations of these suspicious file names appear or where the specific 'AgtaBackstage' string is present, which is indicative of potential malicious activity or persistence mechanisms using software-related naming conventions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Page 55 of 1870