Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the installation or execution of common remote access tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop) using silent or unattended installation flags. This rule explicitly excludes activity originating from known administrative and management platforms such as Microsoft Intune and SCCM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances where rundll32.exe loads a DLL file named Use.dll from a subdirectory named 'ComponentsFolder' within the AppData directory. This pattern is indicative of sandbox evasion techniques used by malware, such as the DarkMe RAT, where the DLL acts as an anti-sandbox gateway to check the execution environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) using either the built-in 'comsvcs.dll' library via 'rundll32.exe' or by requesting specific sensitive process access rights to 'lsass.exe' from unauthorized processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects user-initiated execution of scripts or binaries directly from the root of a drive letter. This pattern is commonly associated with phishing campaigns delivering malicious payloads via mounted ISO or IMG files, which allow attackers to bypass mark-of-the-web or macro security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the installation or execution of common remote access tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop) using silent or unattended installation flags. This rule explicitly excludes activity originating from known administrative and management platforms such as Microsoft Intune and SCCM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the use of legitimate Windows binaries (certutil.exe and bitsadmin.exe) to download files from remote URLs to sensitive or common staging directories (Temp, AppData, ProgramData). Attackers frequently abuse these built-in tools for 'living off the land' (LotL) to retrieve malicious payloads or secondary tools while bypassing traditional signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects persistence attempts on Windows by monitoring for modifications to common Registry Run/RunOnce keys or the creation of executable files within the user startup directory. The rule excludes common legitimate processes like msiexec.exe, trustedinstaller.exe, and explorer.exe to minimize false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects attempts to clear or delete Windows Event Logs using common utilities like wevtutil.exe, PowerShell cmdlets, or direct file system deletion of .evtx files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances where an unauthorized or non-standard source process performs cross-process access (such as OpenProcess or similar operations indicative of code injection techniques like CreateRemoteThread or QueueUserAPC) against a sensitive target host process, such as explorer.exe, svchost.exe, or notepad.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility with either system-level privileges ('/ru SYSTEM') or persistent triggers ('/sc onlogon' or '/sc onstart'). The rule filters out commonly trusted parent processes, highlighting potential persistence mechanisms established by unauthorized or unusual processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the use of rundll32.exe to invoke the MiniDump function of comsvcs.dll targeting the lsass.exe process. This technique is a well-known living-off-the-land (LotL) method used by adversaries to create a memory dump of LSASS, which can then be exfiltrated and analyzed offline using tools like Mimikatz to extract credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of msbuild.exe targeting project files (.csproj, .proj, .xml) located in user-writable directories such as Temp or Downloads, or containing command-line indicators of inline C# task execution (e.g., UsingTask, CodeTaskFactory). This behavior is commonly used for proxy execution and bypassing application allow-listing via LOLBAS.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Active Directory Certificate Services (AD CS) enrollment events (4886/4887) where a request includes an enrollee-supplied Subject Alternative Name (SAN). This behavior is characteristic of ESC1 certificate template abuse (e.g., using tools like Certipy or Certify) to request certificates that impersonate other users or machine accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of named pipes associated with default Cobalt Strike malleable profiles and common open-source C2 frameworks (e.g., Sliver, Havoc) via EDR pipe-creation telemetry. These pipes are frequently used for SMB beacon communication within compromised networks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of named pipes associated with default Cobalt Strike malleable profiles and common open-source C2 frameworks (e.g., Sliver, Havoc) via EDR pipe-creation telemetry. These pipes are frequently used for SMB beacon communication within compromised networks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects execution of Mimikatz or usage of its specific command-line arguments (such as sekurlsa or lsadump modules) which indicate attempted credential dumping from system memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
003
Detects the request for DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights on domain objects, which are highly sensitive Active Directory permissions required to perform DCSync attacks to harvest credentials from Domain Controllers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized modifications to Windows Registry Run/RunOnce keys or the Startup folder. The rule specifically targets persistence attempts where the associated process resides in suspicious directories (Temp, AppData) or uses command-line arguments indicative of script execution (powershell, wscript, mshta, encoded commands, or script extensions). It excludes known legitimate installer behavior involving msiexec or setup processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects WmiPrvSE.exe spawning child processes within 120 seconds of a Type 3 (Network) logon event. This behavior is a common indicator of remote command execution, frequently used by lateral movement tools like Impacket's wmiexec or similar WMI-based remote execution frameworks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests using the weak RC4 encryption type (0x17) from a single account within a 5-minute window. It excludes machine accounts and common system service requests to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Page 75 of 1870