Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
108
Detects the execution of known development, scripting, and administrative tools (e.g., Python, Node.js, GCC, Docker) from non-standard or unauthorized file paths. The rule leverages allowlists for process names, publishers, and trusted installation directories to identify potentially unauthorized usage of powerful tooling often abused by attackers for post-exploitation activities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects the execution of known development, scripting, and administrative tools (e.g., Python, Node.js, GCC, Docker) from non-standard or unauthorized file paths. The rule leverages allowlists for process names, publishers, and trusted installation directories to identify potentially unauthorized usage of powerful tooling often abused by attackers for post-exploitation activities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
This rule monitors network traffic and internal logs for connections to known malicious IP addresses or domain names associated with 'ClickFix' social engineering campaigns (often impersonating services like HBO Max). The logic explicitly filters out known threat intelligence scanners and security researcher probes. It performs correlation by requiring domain/message matches for generic IP-based alerts to reduce noise, and aggregates events per host over 15-minute windows to produce consolidated alerts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects network communication with domains and IP addresses known to be associated with 'ClickFix' social engineering campaigns (specifically those masquerading as legitimate HBO Max or macOS related updates). The rule applies a strict correlation between observed malicious IP traffic and specific DNS requests to reduce noise from IP address reuse or threat intelligence feed probes, while also excluding known security-related processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects unauthorized processes (e.g., cmd.exe, powershell.exe, node.exe) accessing sensitive web browser files like 'Login Data' or 'Cookies' in common browser directories. This behavior is indicative of credential theft or data exfiltration attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
105
Detects unauthorized attempts to exercise Active Directory replication rights (DS-Replication-Get-Changes). This occurs when non-machine accounts access specific control access rights (GUIDs 1131f6aa, 1131f6ad, or 89e95b76) on a domain controller, a common indicator of a DCSync attack used to extract password hashes from Active Directory.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
4016
This rule detects potentially malicious activity involving the modification of Excel macro security settings (specifically VBAWarnings or AccessVBOM) or the creation of autorun.inf files on removable drives. It identifies these behaviors when they coincide with the execution of Synaptics.exe within a 30-minute window, suggesting a potential correlation between local administrative tasks and malicious document-based payloads or portable drive staging.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
24 days ago
001
This rule detects anomalous access patterns on a specific IIS host (agent.3bb.co.th) by comparing recent traffic against a 30-day historical baseline. It identifies requests from accounts or source IPs not seen in the baseline, activity occurring during off-hours, or traffic from external sources. The rule further filters for high-volume or high-path diversity requests, which are indicative of automated reconnaissance or potential brute-force activity against the web application.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
This rule detects anomalous access patterns on a specific IIS host (agent.3bb.co.th) by comparing recent traffic against a 30-day historical baseline. It identifies requests from accounts or source IPs not seen in the baseline, activity occurring during off-hours, or traffic from external sources. The rule further filters for high-volume or high-path diversity requests, which are indicative of automated reconnaissance or potential brute-force activity against the web application.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
This rule detects anomalous access patterns on a specific IIS host (agent.3bb.co.th) by comparing recent traffic against a 30-day historical baseline. It identifies requests from accounts or source IPs not seen in the baseline, activity occurring during off-hours, or traffic from external sources. The rule further filters for high-volume or high-path diversity requests, which are indicative of automated reconnaissance or potential brute-force activity against the web application.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
This rule detects anomalous access patterns on a specific IIS host (agent.3bb.co.th) by comparing recent traffic against a 30-day historical baseline. It identifies requests from accounts or source IPs not seen in the baseline, activity occurring during off-hours, or traffic from external sources. The rule further filters for high-volume or high-path diversity requests, which are indicative of automated reconnaissance or potential brute-force activity against the web application.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
Detects anomalous, high-volume authentication failures originating from a single source IP address targeting multiple distinct internal devices within a short timeframe. This behavior is indicative of a password spraying or brute-force attack.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects anomalous, high-volume authentication failures originating from a single source IP address targeting multiple distinct internal devices within a short timeframe. This behavior is indicative of a password spraying or brute-force attack.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects instances of 'Synaptics.exe' initiating network connections to known suspicious domains or public IP addresses. Legitimate Synaptics driver files should not typically communicate with external C2-related infrastructure or arbitrary public internet sites, suggesting the process might be masqueraded or compromised.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
001
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects the creation or modification of Windows Registry run keys (Run or RunOnce) that attempt to point to executables within 'ProgramData\Synaptics' or named 'synaptics.exe'. This behavior is characteristic of adversaries attempting to establish persistence by masquerading as legitimate Synaptics driver software, while excluding legitimate installation directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
001
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
This rule detects potentially malicious activity involving the modification of Excel macro security settings (specifically VBAWarnings or AccessVBOM) or the creation of autorun.inf files on removable drives. It identifies these behaviors when they coincide with the execution of Synaptics.exe within a 30-minute window, suggesting a potential correlation between local administrative tasks and malicious document-based payloads or portable drive staging.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
001