Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
004
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
004
Detects command-line activity indicative of attempts to perform a DCSync attack, a method used to simulate the replication process of a Domain Controller to extract sensitive Active Directory credentials, including password hashes, using tools like Mimikatz or DSInternals.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of a scheduled task using 'schtasks.exe' that involves suspicious command-line patterns, specifically tasks pointing to potentially volatile directories (temp, appdata, programdata) or tasks executing PowerShell/CMD with common obfuscation/execution arguments such as encoded commands, hidden window styles, or base64 decoding.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential abuse of Windows Management Instrumentation (WMI) for process execution. It monitors for wmic.exe creating processes, PowerShell cmdlets Invoke-WmiMethod or Invoke-CimMethod used for remote execution, and unexpected process spawns from the WmiPrvSE.exe provider service, which are common indicators of lateral movement and remote command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects the execution of common tools and commands used to perform Kerberoasting, a technique where attackers request Kerberos service tickets for user accounts with Service Principal Names (SPNs) in order to perform offline brute-force attacks to recover plaintext credentials. The rule specifically monitors process creation events for known offensive security tools like Rubeus, as well as specific command-line arguments for 'setspn.exe' and various scripts that can be used to identify potential Kerberoasting targets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects persistence mechanisms involving the modification of Windows Registry 'Run' keys or the addition of executable/script files to the Windows Startup folder. It flags suspicious file types (vbs, js, hta, ps1, lnk) or the usage of common living-off-the-land binaries (wscript, cscript, powershell, mshta) when interacting with these persistence locations, while filtering out known benign processes like trustedinstaller.exe and explorer.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of WMI event subscriptions via wmic.exe, PowerShell, or the compilation of MOF files. These techniques are commonly used by adversaries to establish persistence or execute malicious payloads by binding event filters to event consumers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects attempts to bypass or disable the Antimalware Scan Interface (AMSI) in PowerShell by identifying specific commands used to manipulate the AmsiUtils class or its field values in memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the use of legitimate Windows binaries (certutil.exe and bitsadmin.exe) to download files from remote URLs or perform encoding/decoding operations in suspicious directories (Temp, AppData). This activity is commonly used by adversaries for stage-one malware delivery or tool ingress.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances of rundll32.exe or regsvr32.exe executing from suspicious locations or with suspicious command-line arguments (e.g., URLs, JavaScript, or script file extensions) initiated by an unsigned process. This is a common technique used to proxy malicious code execution while evading security monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of PowerShell processes using suspicious command-line flags, encoding, or built-in .NET network download methods (e.g., IEX, Net.WebClient, DownloadString). The rule excludes signed PowerShell binaries and common system management tools like SCCM or monitoring agents to reduce false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects unauthorized or suspicious cross-process access attempts by monitoring relationships between source and target processes. It specifically flags instances where common target processes (e.g., browsers or core system processes) are accessed by a source process that is not on a known allowlist of legitimate parent/child or service-related processes. This pattern is often indicative of process injection or unauthorized memory access attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
004
Detects the creation of Windows Management Instrumentation (WMI) Event Filter, Event Consumer, or FilterToConsumerBinding objects. Attackers use these objects to create event subscriptions that trigger malicious code or scripts upon specific system events, providing a stealthy and persistent execution mechanism.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects network connections, process command line arguments, and DNS queries associated with identified Galago or Panzer ransomware C2, leak site, or contact infrastructure (Tox IDs/Tor .onion addresses).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
103
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
004
Detects the Microsoft HTML Help executable (hh.exe) spawning suspicious child processes such as command interpreters (cmd.exe, powershell.exe) or scripting engines (mshta.exe, wscript.exe). This behavior is characteristic of initial access techniques used by the Kimsuky (APT43) threat group, where malicious CHM files are delivered via email attachments to execute payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects command-line activity indicative of DNS tunneling, often used by OilRig (APT34) for C2 communication via BONDUPDATER. The rule monitors PowerShell or nslookup commands executing DNS TXT record queries paired with long, base64-encoded subdomains, a technique used for exfiltrating data or receiving commands.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects DLL side-loading where a known legitimate signed executable, often associated with security utilities, loads a DLL from a non-standard, user-writable directory (such as Temp, AppData, or ProgramData). This behavior is characteristic of APT10's (Stone Panda/Cicada) historical tradecraft in MSP environments to execute modular PlugX RAT payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects lateral movement via PsExec (PSEXESVC) followed by mass file encryption/rename activities and the creation of ransom note files, characteristic of Wizard Spider's deployment of Conti ransomware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Page 87 of 1870