Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
202
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
202
Detects the loading of the known vulnerable GIGABYTE driver (gdrv.sys) on Windows systems. Attackers leverage this driver as part of Bring Your Own Vulnerable Driver (BYOVD) attacks to perform privilege escalation by exploiting kernel-mode vulnerabilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
106
Detects instances where a suspicious PowerShell, mshta, or pwsh command, typically involving download or obfuscation patterns, is launched as a child process of Windows Explorer within two minutes of a modification to the Explorer RunMRU registry key. This behavior is indicative of an adversary attempting to achieve execution, often following user interaction or persistence triggers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
304
Detects the ClickFix behavioral pattern where Windows Explorer (typically triggered via the Run dialog) directly spawns PowerShell.exe. This activity is indicative of a user being socially engineered into copying and executing a malicious command from a fake CAPTCHA lure directly into the shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
406
This rule detects instances where the Faronics Deploy Agent process initiates the installation or download of ScreenConnect remote access software via PowerShell or the Windows Installer (msiexec.exe). This pattern is often indicative of authorized RMM deployment, but it is also a common tactic for adversaries to establish persistent remote access to endpoints.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
205
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
605
This rule monitors for known malicious file hashes, command and control (C2) domains, and specific download URLs associated with identified threats. It correlates these indicators across process execution, file activity, and network connection logs to identify potential compromises or malicious activity related to the aware-cr1 infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
102
Detects a process querying multiple distinct registry keys associated with virtual environments (VMware, VirtualBox, Wine) in a short time window. This behavior is indicative of environmental profiling performed by malware (such as 2CLoader) to detect sandbox or analysis environments prior to malicious payload execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
102
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
002
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
002
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
002
Detects potentially malicious use of rundll32.exe by monitoring for execution from suspicious directory paths (e.g., Temp, AppData, Downloads), execution with arguments missing common legitimate entry points, unexpected network connections originating from rundll32.exe, or rundll32.exe spawning child processes (excluding known safe binaries like conhost.exe or werfault.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
404
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
002
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
102
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
102
This rule identifies installations of TeamViewer software that are vulnerable to specific CVEs (CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371) by analyzing the 'DeviceTvmSoftwareInventory' dataset. It checks for versioning patterns against known vulnerable build numbers across Windows, Linux, and macOS platforms to pinpoint systems requiring patching.
avatar
Ankit Mehta@Secvyn
Defender - KQL
8 days ago
304
This rule monitors for various indicators of compromise (IOCs) including malicious domains, IP addresses, specific URI paths, file names, and file hashes. It aggregates telemetry from network, file, process, and certificate events to detect potential threats interacting with known bad infrastructure or executing suspicious files associated with malware campaigns.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
404
Detects a sequence of events where a user clicks a shared link to an AI chatbot conversation followed closely (within 15 minutes) by the execution of potentially malicious processes (mshta, powershell, cmd) that include suspicious command-line patterns indicative of ClickFix-style social engineering.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
204
Detects a sequence of events where a user clicks a shared link to an AI chatbot conversation followed closely (within 15 minutes) by the execution of potentially malicious processes (mshta, powershell, cmd) that include suspicious command-line patterns indicative of ClickFix-style social engineering.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
004
Detects a sequence of events where a user clicks a shared link to an AI chatbot conversation followed closely (within 15 minutes) by the execution of potentially malicious processes (mshta, powershell, cmd) that include suspicious command-line patterns indicative of ClickFix-style social engineering.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
104
Page 9 of 1866