Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects instances where attrib.exe is executed with minimal or no command-line arguments, launched by processes other than standard Windows shell processes like cmd.exe, explorer.exe, or powershell.exe. This pattern is often indicative of potential masquerading, where malicious binaries are renamed to mimic legitimate Windows system utilities to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects instances where the rnpkeys.exe process initiates a network connection shortly after its execution. The RNP (OpenPGP) utility is generally used for local cryptographic operations; unexpected network activity from this process may indicate potential misuse, data exfiltration, or malicious use of the tool for command-and-control communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
8148
Detects instances where the process rnpkeys.exe loads suspicious DLLs (rnp.dll or tdwp.dll) without subsequent network activity within a 120-second window. This behavior is indicative of potential DLL side-loading where the process is used to execute malicious payloads without establishing communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
This rule detects potentially malicious C2 communication by monitoring high-frequency HTTP POST requests from the 'rnpkeys.exe' process. It aggregates network events over 30-second windows and flags activity exceeding a threshold of 5 POST requests directed at known suspicious domains or specific high-port network destinations, which is characteristic of beaconing or data exfiltration activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the execution of known NTLM relay and coercion tools (such as PetitPotam, EfsPotato, PrinterBug, DFSCoerce, or Coercer) when attempting to coerce a local authentication or credential relay using the local loopback address. These tools leverage various RPC-based techniques to force the local machine to authenticate to an attacker-controlled source, facilitating NTLM relay attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
4011
Detects the presence or execution of artifacts associated with the TrustSink proof-of-concept (deploy.py, cleanup_eam.py, deploy_state.json), which is used to register or remove rogue Entra authentication providers.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
001
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
304
Detects the creation of a Windows scheduled task where the task name contains the string 'keyroll', often associated with credential rotation or suspicious persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the execution of attrib.exe spawned by known Sauron Loader process names (rnpkeys.exe, rnp.exe, or tdwp.exe). The rule flags instances where attrib.exe is executed without its typical command-line arguments (file attribute flags), suggesting it is being used as a surrogate process for injected C2-tasked shellcode.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
101
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
101
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
101
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
101
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
101
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
001
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
101
Detects network communication associated with the Rapuncel MaaS (Malware-as-a-Service) campaign, specifically identifying the Command and Control (C2) connection, GitHub Pages-based redirect chains, and subsequent delivery of large, suspicious ZIP archives containing renamed executable/system files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects unauthorized processes (excluding firefox.exe and explorer.exe) accessing or modifying sensitive Firefox browser profile files, specifically places.sqlite (history/bookmarks) and cookies.sqlite (session cookies). This activity is often indicative of credential or session hijacking attempts by malware or malicious scripts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
101
Detects multiple, rapid execution sequences of Python or PIP utilities using the 'install' flag with specific common library names often used in reconnaissance or malicious activity. This activity is monitored by looking for repetitive installations of targeted packages within a short timeframe on the same endpoint, which may indicate automated tool deployment or preparation for malicious operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
101
Detects a dual persistence mechanism where an adversary establishes persistence both via a registry Run key and a scheduled task, both named 'WindowsUpdate'. The rule correlates these events occurring on the same device within a 15-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
101
Page 67 of 1870