Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects anomalous network traffic patterns characterized by rapid domain rotation, where multiple distinct domains resolve to a known set of IronToll C2 infrastructure IP addresses within a short timeframe (48 hours). Added an explicit 2-day lookback window — the original query had no time bound at all, so every scheduled run re-scanned the table's entire retention period and would keep re-surfacing the same historical match indefinitely instead of only genuinely recent activity.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects Ruby source files containing a hardcoded RubyGems API key (rubygems_ prefixed token) used for unauthorized gem publish/push actions, as seen in the yardxabc889 package from the GemStuffer campaign
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Detects Ruby source files containing a hardcoded RubyGems API key (rubygems_ prefixed token) used for unauthorized gem publish/push actions, as seen in the yardxabc889 package from the GemStuffer campaign
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
Detects the ShieldCrash CVE-2026-69414 exploit PoC binary/PDB via multiple corroborating distinguishing strings and file size
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
303
This rule detects the creation, modification, or renaming of 'ntdll.dll' within a specific directory path matching the pattern 'ShieldCrash_{GUID}'. This pattern is indicative of potential malicious activity, such as the use of NTFS Alternate Data Streams (ADS) for persistence or execution evasion. The rule explicitly excludes known legitimate system processes that may handle DLL files to minimize noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
003
This rule detects the creation, modification, or renaming of 'ntdll.dll' within a specific directory path matching the pattern 'ShieldCrash_{GUID}'. This pattern is indicative of potential malicious activity, such as the use of NTFS Alternate Data Streams (ADS) for persistence or execution evasion. The rule explicitly excludes known legitimate system processes that may handle DLL files to minimize noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
003
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
103
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
203
Detects the eicar_com.zip test archive used by the ShieldCrash PoC (CVE-2026-69414) to trigger Windows Defender's vulnerable scan/read path, only when observed alongside ShieldCrash binary or staging path/context indicators to reduce false positives from routine EICAR AV testing
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
003
Detects the Warden.dll companion DLL shipped as part of the ShieldCrash (CVE-2026-69414) exploit chain, tightened to require an unsigned/unknown publisher or a suspicious install path alongside the generic filename
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
103
Detects rapid deletion and creation cycles of the WD_SCAN object manager link, a behavioral pattern associated with a Time-of-Check-to-Time-of-Use (TOCTOU) exploit chain targeting Windows Defender (referenced as CVE-2026-69414). The rule monitors for at least three cycle events occurring within a 5-second window, specifically involving the 'WD_SCAN' object identifier.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
203
Detects high-frequency file creation, modification, or renaming activity involving files with the specific '.df_win' extension, likely indicative of mass encryption activity or automated ransomware behavior. The rule excludes known backup and security software processes to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
003
Detects DragonForce ransomware note (readme.txt) referencing known DragonForce Tor negotiation/blog onion addresses
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
003
This rule detects potentially malicious activity where multiple critical processes (such as database engines or email clients) are terminated in a short time frame, correlated with a high volume of file creation or modification events on the same device. This behavior is indicative of destructive activity, such as ransomware encrypting data stores or disabling defensive software.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
203
The following analytic detects renaming of Windows built-in accounts via Event ID 4781.
It identifies renames targeting accounts with well-known reserved RIDs (500-504): Administrator, Guest, krbtgt, DefaultAccount, and WDAGUtilityAccount, by matching the TargetSid field against the S-1-5-21-*-50[0-4] pattern.
Attackers commonly rename the built-in Administrator account to evade detections that alert on the literal account name, while retaining the full privileges of the RID-500 account.
Renaming Guest, krbtgt, or other reserved accounts is highly unusual in any legitimate environment.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
29 days ago
206
Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.
avatar
Ankit Mehta@Secvyn
Defender - KQL
27 days ago
103
Detects outbound network traffic containing cleartext Windows command shell banners, which is highly indicative of a reverse shell connection where a remote attacker has established interactive command-line access to a compromised host.
avatar
Ali AlEnezi@site
avatar
Detections.ai Community
21 days ago
000