Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

The following analytic detects when a unprivileged user changes an Admin accounts password. This is a common artifact of successful exploitation of the BlueHammer Windows Defender privilege escalation. The attacker's process momentarily changes the passwords of high-value local accounts including the built-in Administrator to spawn an authenticated shell session, then immediately reverts the passwords to avoid detection. This uses EventID 4723 to log this activity.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
22071
Detects the usage of command-line flags in AI coding assistant CLIs (such as Claude Code, Amazon Q CLI, and others) that intentionally skip security permissions, bypass approvals, or disable sandbox protections. The rule identifies potential developer activity that may inadvertently reduce the security posture of the development environment.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 days ago
15144
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
avatar
Arnold Chan@slaz
avatar
SlimKQL
3 days ago
19046
Detects the use of msxsl.exe or wmic.exe to process .xsl or .xslt files, potentially indicating the execution of embedded scripts. The rule calculates a risk score based on the combination of the utility name, the presence of an XSL/XSLT file reference in the command line, usage of suspicious file paths (e.g., Temp, AppData), and being launched by potentially suspicious parent processes like cmd.exe or powershell.exe.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
2 days ago
7028
This rule detects suspicious activity related to input capturing, keylogging, or credential access, specifically looking for corresponding 'ActionType' events in Microsoft Defender for Endpoint (DeviceEvents) logs. It alerts on processes performing these actions on devices.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
2 days ago
10021
This rule monitors endpoint telemetry for indicators of compromise (IOCs) associated with known malicious activity. It checks for file creation, process execution, and network connections that match a defined list of malicious file hashes (SHA256, SHA1, MD5), C2 IP addresses, and malicious domains or URL patterns.
avatar
Arnold Chan@slaz
avatar
Hunters
2 days ago
8017
Detects a process other than XBootMgr.exe spawned by XBootMgrSleep.exe.
XBootMgrSleep.exe is a Microsoft-signed Windows Performance Toolkit binary that can execute an arbitrary executable after a delay.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
6 days ago
3043
This rule monitors for known malicious file hashes, command and control (C2) domains, and specific download URLs associated with identified threats. It correlates these indicators across process execution, file activity, and network connection logs to identify potential compromises or malicious activity related to the aware-cr1 infrastructure.
avatar
Arnold Chan@slaz
avatar
SlimKQL
5 days ago
2023
Detects the use of system utilities (wevtutil, PowerShell, wmic, etc.) or log-reading tools (grep, tail) for log enumeration or export when executed by processes that are not standard management or monitoring agents. This pattern is commonly associated with adversary efforts to gain situational awareness or identify security logs.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
12 hours ago
006
This rule detects processes invoking sensitive Windows API functions related to token manipulation (such as DuplicateToken, ImpersonateLoggedOnUser, or CreateProcessAsUser) when initiated by suspicious parent processes like PowerShell, CMD, or WScript. It uses a scoring system that increases risk if the execution occurs from common non-standard directories (e.g., Temp, Public) or is associated with non-system account contexts.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
2 days ago
409
Detects the usage of command-line flags in AI coding assistant CLIs (such as Claude Code, Amazon Q CLI, and others) that intentionally skip security permissions, bypass approvals, or disable sandbox protections. The rule identifies potential developer activity that may inadvertently reduce the security posture of the development environment.
avatar
Goksel Atakan@gokselatakan
Defender - KQL
3 days ago
4011
Detects anomalous process execution and loopback network activity associated with the Model Context Protocol (MCP) 'exec_in_session' method. This pattern indicates an adversary potentially abusing the AI coding assistant's MCP server capabilities to execute arbitrary commands as a C2 channel.
avatar
Arnold Chan@slaz
avatar
Hunters
2 days ago
708
Detects obfuscated PowerShell scripts that enumerate Microsoft.PowerShell.Utility exported commands
and invoke cmdlets indirectly by array index. This can be used to evade detections
that look for explicit strings such as Invoke-RestMethod or Invoke-Expression.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 days ago
708
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
409
The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
209
Detects a suspected ClickFix social engineering attack where a user is tricked into pasting malicious commands into Windows Terminal, leading to a PowerShell download, followed by the appearance of specific known malicious artifacts (LockScreenContentServer.exe, dui70.dll, or 1.bat) within 15 minutes on the same device.
avatar
ᴅᴜᴛᴄʜʙᴏʏ 😎@dutchboy
avatar
DROID
6 days ago
4020
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
1808
This rule detects network communication, DNS queries, email interactions, and URL clicks associated with known TA419 threat actor infrastructure. It monitors multiple telemetry sources to identify indicators of compromise (IOCs) such as specific domains, IP addresses, and email addresses.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
4 days ago
4011
This rule monitors for potentially malicious use of Windows Subsystem for Linux (WSL) binaries. It detects the execution of common command-line tools for reconnaissance, download, or lateral movement within the WSL environment, identifies the use of WSL to execute Windows 'living-off-the-land' binaries (Lolbins), and flags the installation of WSL components.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
12 hours ago
104
Detects the creation or modification of Python configuration files (.pth, sitecustomize.py, usercustomize.py) within site-packages or dist-packages directories when not initiated by recognized Python package managers. Such files can be abused to achieve arbitrary code execution upon Python interpreter startup, a common method for persistence or local privilege escalation in Python environments.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
13 hours ago
204
Sweeps network connection, HTTP/proxy, file, and process telemetry for exact matches against known Cling botnet indicators: dedicated STUN C2/operator IPs, Cling MIPS loader staging URLs, and known Cling sample SHA256 hashes. Tightened to exclude broad domain-level matching on stun.l.google.com (legitimate, ubiquitous Google STUN infrastructure that Cling spoofs/abuses rather than owns) and to match payload-staging hosts only by full URL rather than bare IP, reducing false positives from shared/compromised hosting and unrelated legitimate STUN traffic.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
3 days ago
007
Page 1 of 1866