Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
000
Detects the modification or creation of the registry key '.mollis' within Software\Classes, which is used by the Star Blizzard (RedFlick) CPL downloader to store an encrypted AES key. This activity is performed by common Windows processes such as control.exe, rundll32.exe, or regsvr32.exe.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
000
Detects the modification or creation of the registry key '.mollis' within Software\Classes, which is used by the Star Blizzard (RedFlick) CPL downloader to store an encrypted AES key. This activity is performed by common Windows processes such as control.exe, rundll32.exe, or regsvr32.exe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects a specific multi-stage infection chain associated with Star Blizzard. The sequence begins with a command shell launched under conhost.exe executing SSH with PermitLocalCommand enabled, followed by the execution of a control panel (.cpl) file via control.exe within a two-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects successful RDP (Remote Desktop Protocol) logon events (Event ID 4624, Logon Type 10) where the source IP address is outside the predefined internal network ranges. This behavior is indicative of potential lateral movement, where an attacker attempts to access internal systems from an external, non-corporate source.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects unauthorized processes requesting memory access to lsass.exe with read permissions commonly associated with credential dumping techniques like Mimikatz. It identifies remote handle requests to lsass.exe, which are frequently used by tools deployed via network services or remote execution methods to extract credentials from memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects the use of native Windows administration utilities (vssadmin, wbadmin, bcdedit, wmic) to delete volume shadow copies, backup catalogs, or disable system recovery configurations. The rule specifically monitors for patterns where these commands are executed across multiple hosts or in rapid succession by the same account, behavior frequently observed during the precursor stages of ransomware deployment, such as the ShinyHunters ShinySp1d3r campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of TruffleHog, an automated secret-scanning CLI tool, often utilized by threat actors to harvest sensitive credentials from local filesystems, repositories, environment variables, or CI/CD configuration files following unauthorized access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the execution of the GigaWiper malware or the use of common system commands associated with destructive data activities, such as recursive file removal, disk formatting, or secure data overwriting, often used by threat actors for extortion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a burst of Kerberos TGS-REQ (Ticket-Granting Service Request) messages using RC4 encryption (etype 0x17) over UDP or TCP port 88. A high volume of these requests from a single source within a short timeframe is indicative of Kerberoasting, a technique where an attacker requests service tickets to perform offline password cracking of service account credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects anomalous MS-DRSR DRSGetNCChanges requests occurring between hosts where the requester is not a recognized Domain Controller. This pattern is commonly used by attackers to perform a DCSync attack, allowing for the replication of sensitive Active Directory data such as user password hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects anomalous network traffic patterns characteristic of the PetitPotam exploit, specifically targeting the MS-EFSRPC interface on Windows SMB pipes. This behavior is used to force a remote system to initiate authentication to a specified target, facilitating NTLM relay attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects NTLM authentication attempts targeting administrative network shares (ADMIN$ or C$) over the SMB protocol. This behavior is a common indicator of lateral movement techniques such as Pass-the-Hash, where an adversary uses captured NTLM hashes to authenticate to remote systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Page 98 of 1870