Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the abuse of common Windows LOLBins (Living Off the Land Binaries) like regsvr32, mshta, certutil, and rundll32 to proxy the execution of remote scripts, DLLs, or malicious payloads, a technique often used to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation or modification of Windows Registry Run or RunOnce keys where the associated file path points to suspicious directories (e.g., Temp, AppData, ProgramData, Users\Public) or utilizes living-off-the-land binaries (rundll32.exe, regsvr32.exe) residing outside of the protected System32 directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of PowerShell with suspicious command-line flags (EncodedCommand, NoProfile, WindowStyle Hidden, ExecutionPolicy Bypass) combined with either potential Base64-encoded payloads or network-based download cradles (e.g., Invoke-Expression, WebClient).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Windows Security (1102) or System (104) log clearing events that occur within 30 minutes of privileged activity (new account creation, group membership changes, or service installation) on the same host, sharply reducing false positives versus alerting on log clears alone.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential Cobalt Strike SMB beacon activity by identifying the creation of suspicious named pipes (commonly associated with Cobalt Strike) and correlating them with low-jitter, uniform outbound network communication patterns typical of command and control (C2) beaconing behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Active Directory enumeration consistent with BloodHound/SharpHound collection: SharpHound.exe or PowerView cmdlet process/command-line signatures, matching PowerShell script block log content, and bursts of LDAP traffic (ports 389/636) from a single source to a domain controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule identifies potential lateral movement or account compromise by detecting accounts that have performed NTLM network logons or authentication (Events 4624/4776) without corresponding Kerberos pre-authentication or interactive logon events within a 15-minute window. This pattern often indicates the use of stolen credentials (e.g., Pass-the-Hash) to access network resources rather than standard interactive user activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Windows Security (1102) or System (104) log clearing events that occur within 30 minutes of privileged activity (new account creation, group membership changes, or service installation) on the same host, sharply reducing false positives versus alerting on log clears alone.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential Cobalt Strike SMB beacon activity by identifying the creation of suspicious named pipes (commonly associated with Cobalt Strike) and correlating them with low-jitter, uniform outbound network communication patterns typical of command and control (C2) beaconing behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the Print Spooler service (spoolsv.exe) spawning a shell/script interpreter or rundll32.exe as a child process, or loading a DLL from a driver-store/temp/ProgramData path — the process-injection and arbitrary-DLL-load pattern characteristic of PrintNightmare (CVE-2021-34527) exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Active Directory enumeration consistent with BloodHound/SharpHound collection: SharpHound.exe or PowerView cmdlet process/command-line signatures, matching PowerShell script block log content, and bursts of LDAP traffic (ports 389/636) from a single source to a domain controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of a process from a non-standard writable directory (e.g., Temp, Downloads, AppData) which subsequently loads an unsigned DLL from the same directory within two minutes of process creation. This behavior is indicative of DLL side-loading, where an adversary uses a legitimate, potentially signed application to load a malicious DLL, bypassing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the modification of Windows Run or RunOnce registry keys to execute applications from suspicious paths (e.g., Temp, AppData) or trigger PowerShell commands that contain suspicious arguments or patterns, indicating potential persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of scheduled tasks using schtasks.exe that execute common script interpreters (powershell.exe, wscript.exe, mshta.exe, cscript.exe) from user-writable or temporary directories (Temp, AppData, ProgramData, Users\Public). This activity often indicates an attempt to establish persistence or run malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects unauthorized or suspicious processes attempting to access the memory of the Local Security Authority Subsystem Service (LSASS). It specifically targets memory access (EventID 10) with sensitive access masks (e.g., PROCESS_QUERY_LIMITED_INFORMATION, PROCESS_VM_READ) originating from processes executing from suspicious locations such as Temp, AppData, Downloads, or randomly generated executable names. This method is often used by modern credential dumpers, such as those utilizing direct or indirect syscalls, to bypass userland security hooks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the execution of known living-off-the-land binaries or network utilities initiated by or involving processes related to the Semantic Kernel framework (e.g., SKAgent, kernel.run). This pattern is often indicative of automated execution, potentially associated with agent-based activity or malicious orchestration leveraging AI framework components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
304
Detects the creation of a remote thread (Sysmon Event ID 8) by a process into a set of common host processes (e.g., svchost.exe, explorer.exe) where the starting address of the thread does not map to a known loaded module. This behavior is highly indicative of reflective code injection or shellcode execution within the address space of a remote process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects suspicious PowerShell ScriptBlock logs (Event ID 4104) that attempt to bypass security features like AMSI or ETW while employing common obfuscation techniques such as Base64 encoding, reflection, or character concatenation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the installation or execution of common Remote Monitoring and Management (RMM) tools (e.g., ScreenConnect, AnyDesk, Atera) that are initiated from potentially untrusted parent processes like browsers, mail clients, or archive utilities, or that exhibit a code signing discrepancy. The rule further correlates these installation events with subsequent modifications to the Windows firewall within a two-hour window, which is indicative of an adversary establishing remote access persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the use of BITSAdmin to download files to suspicious directories (Temp, AppData, ProgramData) or to register persistent command execution via the /SetNotifyCmdLine parameter. This detection correlates process execution events with BITS Client operational log events to confirm the completion or status of the BITS job.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
Page 83 of 1870