Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects high-volume RDP X.224 connection requests originating from a single source within a short timeframe, which is a strong indicator of a brute force or password spraying attack targeting Remote Desktop Protocol services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects outbound network traffic matching Stratum protocol JSON-RPC methods (mining.subscribe, mining.authorize, mining.submit) typically used by XMRig and other cryptomining software to communicate with a mining pool. The rule monitors for established TCP connections on non-standard ports, excluding common web ports 80 and 443.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
2011
This rule detects instances where the WMI Provider Host process (wmiprvse.exe) initiates a child process. While WMI is a legitimate administrative tool, it is frequently abused by attackers for lateral movement, remote code execution, and persistent event subscriptions. Monitoring for child processes spawned by wmiprvse.exe can highlight potentially malicious activity triggered via WMI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
105
Detects the deletion of volume shadow copies using standard Windows utilities vssadmin.exe or wmic.exe. This activity is a common indicator of ransomware or other destructive attacks attempting to inhibit system recovery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects repeated file creation or modification events involving the specific file 'bot_log.txt' in directory paths containing '\Temp\' on endpoints where 'msedge_proxy.exe' is also running. This pattern is indicative of potential data staging or logging activities by an unauthorized proxy or tunnel process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Matches known SHA-256 hashes for the BotHelper stager (WindowsUpdate.exe) and RAT (msedge_proxy.exe)
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects potential command and control (C2) activity associated with the BotHelper malware. The rule correlates a process downloading files or DLL plugins from specific C2 URL paths ('/uploads/Files/' or '/uploads/Plugins/') with a subsequent report of task execution status ('task_run.php' or 'task_failed.php') originating from the same process within a 10-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects host-control and management tasks (e.g., shutdown, logoff, scheduled task modification) executed as child processes of the msedge_proxy.exe process. This behavior is indicative of the BotHelper malware implant managing infected endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects usage of Crowdstrike Real Time Response (RTR) to execute a "runscript" command.
This can be used by malicious actors with access to the Crowdstrike Dashboard to execute commands on remote managed hosts.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
9 days ago
001
Detects the execution of a .pif (Program Information File) process where the filename contains keywords suggestive of image files (e.g., 'image', 'photo', 'scan'). Adversaries often use this technique to trick users into executing malicious code by masquerading the file type.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
006
Detects the DarkMe downloader chain involving staging via WebDAV UNC paths, extraction of password-protected archives using 7-Zip, and subsequent execution using rundll32.exe with the specific RunDllEntryPointW export, which is indicative of this malware's execution flow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
006
This rule detects network activity associated with the DarkMe RAT, specifically targeting outbound TCP connections or DNS resolutions involving known C2 domains by the rundll32.exe process. This activity is indicative of the malware's post-injection C2 registration and beaconing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
006
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
003
Detects ClickFix-style social engineering attacks where users are tricked into pasting malicious payloads into the Windows Run dialog. The rule monitors for common scripting interpreters (powershell.exe, cmd.exe, mshta.exe, rundll32.exe) spawned by explorer.exe or mstsc.exe with suspicious command-line patterns indicative of payload delivery, such as obfuscated strings, hidden windows, or short-URL downloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects instances where a signed executable, typically a security or trusted system binary, loads an unsigned DLL from a user-writable, non-default directory (e.g., Temp, AppData, ProgramData). The rule specifically targets common system or vendor library names, indicating potential DLL search-order hijacking used to execute malicious code within a trusted process context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects suspicious network activity or credential exfiltration attempts occurring during package manager installation processes (npm, pip, yarn). The rule monitors for lifecycle scripts (e.g., preinstall, postinstall) spawning network utilities to external destinations or accessing common CI/CD secrets like AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
102
Detects execution of mshta.exe when initiated by common office or web browser applications, or when command arguments include external network references (URLs/UNC paths) or script protocols (vbscript/javascript), which are common patterns for LOLBAS-based initial access or exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
215
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
302
Page 57 of 1870