Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution of the Microsoft HTML Application host (mshta.exe) when it is used to launch scripts from remote URLs (http/https/ftp) or when it spawns common command-line shells and scripting engines, which is a common indicator of living-off-the-land techniques used to execute malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects various forms of process injection (Remote Thread, APC, Map View of Section) targeting common, high-value Windows processes such as explorer.exe, lsass.exe, and web browsers. This behavior is a common technique used by attackers to gain persistence, elevate privileges, or execute code within the context of legitimate system or user-level processes to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized attempts by processes to access the memory of sensitive Windows system processes, specifically LSASS.exe or winlogon.exe, using suspicious access masks associated with memory dumping or credential harvesting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the abuse of signed Windows system binaries regsvr32.exe and rundll32.exe for proxy execution, defense evasion, and credential access. The rule identifies suspicious command-line patterns including Squiblydoo (regsvr32 with remote scriptlets), rundll32 executing JavaScript via mshtml.dll, rundll32 performing LSASS credential dumping via comsvcs.dll, and the loading of DLLs from untrusted user-writable locations like Temp or Downloads folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Kerberos service ticket requests (EventID 4769) that utilize RC4 encryption (0x17) instead of the more secure AES encryption. Attackers often force RC4-HMAC when requesting service tickets for accounts with Service Principal Names (SPNs) because these tickets are susceptible to offline brute-force attacks to recover service account passwords. This technique is a common precursor to lateral movement and privilege escalation in Active Directory environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential Pass-the-Hash (PtH) activity by monitoring for NTLM network logons (Logon Type 3) that are associated with a blank WorkstationName, often indicating spoofing. This pattern is correlated with the assignment of special privileges (EventID 4672) to capture scenarios where stolen NTLM hashes are replayed for lateral movement into a system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the abuse of signed Windows system binaries regsvr32.exe and rundll32.exe for proxy execution, defense evasion, and credential access. The rule identifies suspicious command-line patterns including Squiblydoo (regsvr32 with remote scriptlets), rundll32 executing JavaScript via mshtml.dll, rundll32 performing LSASS credential dumping via comsvcs.dll, and the loading of DLLs from untrusted user-writable locations like Temp or Downloads folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the task execution path points to common script interpreters (PowerShell, WScript, CScript, MSHTA, Rundll32) or is located in common user-writable directories (Users, Temp, AppData). Additionally, it flags tasks configured to execute under the 'SYSTEM' account, which is a common technique used to achieve persistence with elevated privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of PowerShell commands that leverage obfuscation or evasion techniques such as Base64 encoded commands, hidden window styles, in-memory script downloads via IEX, and common string obfuscation methods like backtick insertion, character concatenation, and casting. These techniques are frequently used by adversaries to bypass command-line monitoring and execute malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of a new Windows service (EventID 7045) where the binary path references the ADMIN$ share, contains known remote execution tool artifacts (e.g., PSEXESVC, PAExec), or uses a randomized/GUID-like naming convention. This pattern is indicative of classic SMB-based lateral movement where an adversary performs remote code execution via service installation following credential compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the spawning of cmd.exe, powershell.exe, or powershell_ise.exe by the WMI Provider Host (wmiprvse.exe). This pattern is frequently used for fileless lateral movement, as threat actors leverage WMI (Win32_Process.Create) to execute remote commands which manifests as wmiprvse.exe launching a shell on the target host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the use of legitimate Windows system utilities certutil.exe and bitsadmin.exe to perform remote file downloads or decode remote content. Adversaries often use these dual-use tools to bypass network security controls by masquerading as standard system processes for staging second-stage payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the loading of suspicious kernel drivers (Sysmon Event ID 6) that are unsigned, have invalid/revoked signatures, or are located in user-writable directories (e.g., Temp folders). This rule aims to identify Bring Your Own Vulnerable Driver (BYOVD) attacks, where adversaries load vulnerable drivers to escalate privileges or bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by monitoring script block logs for specific patterns used to disable or manipulate memory scanning mechanisms, a common precursor to executing malicious, memory-resident payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Kerberos ticket requests (AS-REQ/TGS-REQ) that exhibit characteristics of a forged Golden Ticket, specifically the use of legacy RC4 (0x17) encryption in environments where AES is typically preferred, non-standard ticket options (0x40810000), and requests for accounts or services that lack a corresponding legitimate authentication event. This detection aims to identify the post-compromise phase where an adversary uses a forged TGT to impersonate domain accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the use of native Windows utilities such as vssadmin, ntdsutil, or diskshadow to create volume shadow copies for the purpose of accessing or extracting the ntds.dit Active Directory database file. This activity is a common indicator of credential theft attempts where adversaries bypass file access protections to offline-process the database and retrieve password hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized access attempts to SYSTEM-level processes (winlogon.exe, services.exe) using specific access rights such as PROCESS_DUP_HANDLE or PROCESS_QUERY_INFORMATION. This behavior is indicative of token stealing or impersonation attempts often utilized by tools like JuicyPotato, RoguePotato, and PrintSpoofer to escalate privileges to SYSTEM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential process injection attempts where a browser or Office application attempts to write to the memory or create a remote thread within high-value or trusted system processes like svchost.exe or explorer.exe. This activity is indicative of defense evasion techniques such as DLL or PE injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects suspicious process access to the Local Security Authority Subsystem Service (lsass.exe) with access masks commonly associated with credential dumping techniques. The rule specifically monitors for high-privileged access requests by unauthorized processes, excluding known legitimate tools and system services, to identify attempts to extract cached authentication materials such as NTLM hashes or Kerberos tickets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Page 81 of 1870