Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
000
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
000
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
000
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
000
Detects the execution of 'LevelInstaller.exe' with specific installation arguments ('--action install --force --key') in conjunction with the presence of the 'level.exe' binary in its designated Program Files directory. The rule optionally identifies related scheduled task creation for 'Level Watchdog' and network activity associated with the 'level.io' domain or specific IP address.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
303
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
104
This rule detects rundll32.exe executing a DLL from the ProgramData directory and subsequently establishing five or more outbound network connections to external IP addresses over non-standard ports (excluding 80 and 443) within a one-hour window. This behavior is indicative of a potential malware beaconing or data staging activity using a proxy binary to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
103
Detects modifications to the 'PlugPlay' Windows service using 'sc.exe', specifically involving changes to the binary path (binpath) and subsequent service status changes (start/stop) within a short timeframe (30 minutes). This behavior is often associated with the persistence or hijacking of services to execute malicious files, specifically targeting Microsoft Office or Copilot-related process names.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects anomalous file activity associated with the PaperCut application (pc-app.exe), characterized by the creation of numbered binary chunks (.bin) followed by the creation of a status log file (pcxboot_l.txt) and the subsequent deletion of the binary chunks. This behavior is indicative of an in-memory Java payload loader pattern used to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects credential-dumping modules (such as nanodump, hashdump, and lsadump variants) associated with AdaptixC2 framework being invoked or used by the 'mscopilot.exe' process. The rule monitors for command-line arguments indicating credential extraction, unauthorized attempts to open handle to lsass.exe, and access to sensitive registry hives (SAM, Security, LSA) by the suspect process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects the deletion, truncation, or modification of critical PaperCut server logs and application files (server.log, pcxboot_l.txt, .bin files). This activity is associated with attempts to conceal exploitation of PaperCut vulnerabilities (e.g., CVE-2026-82078/81578) by clearing logs or tampering with binaries, typically executed by the PaperCut application processes themselves (pc-app.exe or Java runtime).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
This rule detects suspicious activity originating from the PaperCut 'pc-app.exe' process. It monitors for the creation or execution of a file named 'mscopilot.exe' within the non-standard directory 'C:\Microsoft.Office365\'. The rule matches based on a known malicious SHA1 hash or the specific file-write-then-execute behavior within a one-hour window, indicating potential AdaptixC2 loader activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects instances where the WMI Provider Host (wmiprvse.exe) spawns suspicious child processes such as cmd.exe, powershell.exe, or rundll32.exe, which are correlated with inbound network connections on ports 135 (RPC/DCOM) or 445 (SMB). This behavior is characteristic of lateral movement techniques used by tools like Impacket's wmiexec.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (lsass.exe) with sensitive access rights (e.g., PROCESS_VM_READ, PROCESS_QUERY_INFORMATION). These access patterns are frequently utilized by credential dumping tools like Mimikatz, ProcDump, or malicious abuse of system utilities to extract plaintext passwords or NTLM hashes from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of PowerShell or PWSH with encoded command flags (-EncodedCommand, -enc, -e), which is a common technique used by adversaries to hide malicious scripts or payloads from inspection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Page 79 of 1870