Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects legitimate, signed executables from trusted system locations (e.g., System32) loading DLLs from non-standard, user-writable directories (e.g., Temp, AppData). This activity is a classic indicator of DLL side-loading, where an adversary places a malicious DLL in a directory to be picked up by a legitimate application, enabling the execution of malicious code under the context of a trusted process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects suspicious cross-process memory operations where a source process requests process creation/write permissions on a target process (e.g., browsers, explorer.exe, or svchost.exe), followed immediately by the execution of a remote thread injection technique such as CreateRemoteThread, QueueUserAPC, or NtCreateThreadEx within the same process pair.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
104
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
004
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
004
Detects the use of the built-in Windows utility rundll32.exe to execute the MiniDump functionality within comsvcs.dll against the Local Security Authority Subsystem Service (LSASS). This technique is a common method for attackers to bypass signature-based security tools and obtain sensitive credentials from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
604
Detects the abuse of the legitimate Windows system binaries regsvr32.exe and rundll32.exe to execute remote scripts or scriptlets, a technique often used to bypass application control and proxy execution of malicious code (similar to Squiblydoo).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of reg.exe with the 'save' command to extract the SAM, SYSTEM, or SECURITY registry hives to disk. This technique is commonly used by attackers to offline extract credential hashes, facilitating pass-the-hash attacks and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
004
Detects the execution of PowerShell with encoded commands (e.g., -EncodedCommand or -enc) combined with common download cradle indicators such as IEX, Net.WebClient, or DownloadString. This combination is highly indicative of fileless malware execution, initial access payload staging, or defense evasion techniques often employed by threat actors to bypass command-line monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized directory replication requests (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) made against Active Directory by a user or computer account that is not a domain controller. This behavior is indicative of a DCSync attack, typically performed by tools like Mimikatz to extract password hashes for all domain accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the task is configured to run in the security context of the SYSTEM account or executes suspicious binaries like PowerShell, mshta, or other living-off-the-land binaries. This behavior is indicative of potential persistence mechanisms employed by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the abuse of the built-in Windows utility 'certutil.exe' to download remote files using URL cache functionality or to deobfuscate base64-encoded payloads. This is a common LOLBin (Living-off-the-Land Binary) technique used in phishing loaders, malware delivery, and post-exploitation toolkits.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of WMI permanent event subscriptions, including the instantiation of __EventFilter, __EventConsumer, and __FilterToConsumerBinding classes. This mechanism is frequently used by adversaries for fileless and reboot-resilient persistence, as it allows for arbitrary code execution triggered by system events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential Kerberoasting activity by monitoring Windows Security Event ID 4769 for TGS service ticket requests using weak RC4 encryption (etype 0x17). It correlates these individual requests to identify a single user account requesting an abnormally high volume of service tickets within a 10-minute window, which is highly characteristic of automated SPN enumeration and cracking tools like Rubeus or Impacket.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances where a digitally signed executable loads a DLL from a non-standard, user-writable directory (such as Downloads, Desktop, Temp, or AppData). This behavior is characteristic of DLL side-loading, an evasion technique used to execute malicious code by placing a rogue DLL in a location where a legitimate binary might search for its dependencies, often used by threat actors to persist or maintain covert execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects lateral movement activities involving the use of PsExec-style tools or the manual creation of remote services to execute commands. This behavior often leverages SMB admin shares (ADMIN$, C$) to drop and execute binaries or scripts, a technique frequently observed in ransomware campaigns and red team engagements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects artifacts and command-line patterns associated with Impacket utility suite modules, specifically wmiexec.py, smbexec.py, and secretsdump.py. These tools are commonly used by adversaries for remote command execution, lateral movement, and dumping of sensitive domain or system credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of legitimate developer utilities msbuild.exe, regasm.exe, and regsvcs.exe in manners consistent with malicious proxy execution. This includes the use of inline tasks in project files, remote network-sourced project files, or specific command-line arguments (such as /codebase or /unregister) that suggest the abuse of these binaries to execute arbitrary code or bypass application control mechanisms, while excluding known legitimate developer-related parent processes and build workflows.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Microsoft Office applications or scripting engines spawning schtasks.exe to create or modify a scheduled task that executes as the SYSTEM user upon system startup or login. This behavior is highly indicative of persistence mechanisms used by malicious documents or scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Page 77 of 1870