Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects modifications to Windows Registry Run/RunOnce keys or file creation events in the Startup folder by processes not identified as standard system installers or Windows Explorer, indicating potential persistence attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of scheduled tasks using schtasks.exe that involve suspicious arguments (such as encoded commands, execution from volatile directories like Temp/AppData, or run-once triggers) shortly after a file has been downloaded into a temporary or user-writable directory. This pattern is commonly indicative of an adversary establishing persistence for downloaded malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects execution of rundll32.exe or regsvr32.exe with potentially malicious command-line arguments, including references to external URLs, protocol handlers like javascript:, or loading DLLs from user-writable directories (Temp, AppData, Downloads). This behavior is characteristic of Living-off-the-Land (LotL) techniques used to proxy execution and bypass application control or security monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Windows Event 4662 indicating the use of DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights from a host that is not a known domain controller. This behavior is highly indicative of credential dumping via DCSync, commonly associated with tools like Mimikatz.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential lateral movement via Remote Desktop Protocol (RDP) by identifying a single user account establishing RemoteInteractive (logon type 10) sessions to three or more distinct destination hosts within a 15-minute timeframe. This pattern is indicative of an attacker attempting to traverse a network from a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances where one process initiates an injection mechanism (such as CreateRemoteThread, QueueUserAPC, or NtMapViewOfSection) into another process. The rule specifically alerts when these actions target common, high-value, or frequently abused processes such as explorer.exe, svchost.exe, or web browsers (chrome.exe, firefox.exe, msedge.exe), which are common targets for maintaining persistence or evading detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects anomalous lateral movement behavior by monitoring Windows Event 4624 (Logon Type 3) using NTLM authentication. The rule triggers when a single user account authenticates to five or more distinct hosts within a five-minute window, a pattern frequently associated with Pass-the-Hash attacks where captured credentials are used to spread across a network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects non-SYSTEM processes enabling SeDebugPrivilege or SeImpersonatePrivilege shortly before launching a process as the SYSTEM user. This behavior is highly indicative of token manipulation and impersonation techniques (e.g., Potato-family exploits) used to elevate privileges from a standard or administrative account to SYSTEM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects attempts to disable security services (Windows Defender, EDR agents), modify audit policies via auditpol, or stop/clear the Windows Event Log service. This behavior is a common precursor to post-compromise activity intended to blind defenders and conceal malicious actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects an attempt to perform Active Directory replication (DS-Replication-Get-Changes or DS-Replication-Get-Changes-All) initiated by a machine that is not a recognized Domain Controller. This is a common indicator of credential dumping or unauthorized domain information gathering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
000
This rule detects the creation of scheduled tasks using either 'schtasks.exe' or PowerShell ('powershell.exe', 'pwsh.exe') with suspicious parameters. It flags tasks created in temporary directories (e.g., AppData, Temp, ProgramData, Windows\Temp) or tasks executed with 'highest' privileges or hidden configurations, often used for persistence or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
000
Detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos TGS requests (Event ID 4769) for tickets encrypted with RC4 (0x17) within a short timeframe. The rule tracks the count of requests and the diversity of Service Principal Names (SPNs) requested by a specific user account, excluding machine accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential persistence mechanisms on Windows systems by monitoring for the creation or modification of Registry 'Run' or 'RunOnce' keys, as well as the creation of files within the Windows Startup folder. These actions are commonly used by adversaries to ensure malicious code executes automatically upon user login or system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects execution of regsvr32.exe with command-line arguments that include a remote URL ('/i:http...') combined with silent, unregistered, and notification-free execution flags ('/s', '/u', '/n'). This behavior is characteristic of the 'Squiblydoo' technique, where attackers use Regsvr32 to execute arbitrary scriptlets from remote servers to bypass application whitelisting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances of rundll32.exe being used with suspicious command line arguments, such as referencing JavaScript, loading Control Panel applets (.cpl) via shell32.dll from non-standard locations, or executing DLLs directly from user-writable directories (Temp, AppData, Downloads, ProgramData). These patterns are common techniques used by adversaries to proxy execution and evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential lateral movement and persistence activities by identifying suspicious Windows service installations via event ID 7045. The rule flags services with suspicious names or paths (e.g., Temp folders, Public directory) and correlates them with incoming SMB connections (port 445) or services spawned directly by services.exe from suspicious locations, aggregated by host and remote IP.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Page 80 of 1870