Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the creation, modification or deletion of a WMI permanent event subscription using Sysmon EventID 21.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
001
Detects anomalous lateral movement behavior where a successful NetScaler VPN or gateway session is followed immediately by internal remote service logons (RDP, SSH, WinRM) or network connections from the same source IP. This pattern is indicative of potential exploitation of Citrix NetScaler vulnerabilities (e.g., CVE-2026-88771, CVE-2026-88772) or credential abuse to move laterally into the internal environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
209
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
0112
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
002
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
102
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
002
Detects the execution of the 'rnpkeys.exe' file from the 'C:\ProgramData\keyroll\' directory. The location and filename are highly atypical and could indicate unauthorized tool usage, potential persistence, or malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
0014
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
8 days ago
105
Detects instances where a process writes to known persistence locations, including Windows Registry Run keys, the Windows Startup folder, Linux shell profile configuration files (.bashrc/.bash_profile), and system-level task directories (cron and systemd units). This activity is often indicative of malicious persistence mechanisms, such as those used by compromised AI agents or backdoors to survive system reboots.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
405
The following analytic identifies a possible non-common browser process accessing its browser user data profile.
This tactic/technique has been observed in various Trojan Stealers, such as SnakeKeylogger, which attempt to gather sensitive browser information and credentials as part of their exfiltration strategy.
Detecting this anomaly can serve as a valuable pivot for identifying processes that access lists of browser user data profiles unexpectedly.
This detection uses a lookup file `browser_app_list` that maintains a list of well known browser applications and the browser paths that are allowed to access the browser user data profiles.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
001
The following analytic identifies potential DLL search order hijacking or DLL sideloading by detecting known Windows libraries loaded from non-standard directories. It leverages Sysmon EventCode 7 to monitor DLL loads and cross-references them with a lookup of known hijackable libraries. This activity is significant as it may indicate an attempt to execute malicious code by exploiting DLL search order vulnerabilities. If confirmed malicious, this could allow attackers to gain code execution, escalate privileges, or maintain persistence within the environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
101
The following analytic identifies the creation of Dynamic Link Libraries (DLLs) with a known history of exploitation in atypical locations. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and filesystem events. This activity is significant as it may indicate DLL search order hijacking or sideloading, techniques used by attackers to execute arbitrary code, maintain persistence, or escalate privileges. If confirmed malicious, this activity could allow attackers to blend in with legitimate operations, posing a severe threat to system integrity and security.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
001
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
204
Detects a suspected ClickFix social engineering attack where a user is tricked into pasting malicious commands into Windows Terminal, leading to a PowerShell download, followed by the appearance of specific known malicious artifacts (LockScreenContentServer.exe, dui70.dll, or 1.bat) within 15 minutes on the same device.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
204
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
306
The following analytic identifies Living Off the Land Binaries and Scripts (LOLBAS) that can legitimately initiate public network connections but are communicating over uncommon destination ports.
It leverages the Network Traffic data model and applies per-binary common-port exclusions to reduce false positives while preserving suspicious non-standard communication.
This behavior may indicate payload download, command-and-control, proxy execution, or attempts to blend malicious traffic into trusted Windows binaries.
Join this detection with the Process Execution events to provide context and avoid false positives.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
2031
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
105
Detects indicators associated with the ChatGPT Custom GPT ClickFix campaign across process, network connection, DNS, and HTTP telemetry: known malicious file hashes, C2 IP addresses, the chattypetty.com domain, and known payload-hosting URLs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
605
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
avatar
Des Wass@DesWass
avatar
SlimKQL 2026
18 days ago
33085
Detects process/file hashes associated with the ChatGPT Custom GPT ClickFix
campaign via Windows process_creation telemetry. Split from the combined IOC
hunt: Sigma supports only one logsource per rule, so IP/domain/URL matching live
in separate network_connection and dns_query rules.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
105
Detects process/file hashes associated with the ChatGPT Custom GPT ClickFix
campaign via Windows process_creation telemetry. Split from the combined IOC
hunt: Sigma supports only one logsource per rule, so IP/domain/URL matching live
in separate network_connection and dns_query rules.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
005
Page 8 of 1866