Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
Detects file creation on a removable drive followed by process execution from that drive shortly after mounting.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
Detects instances where node, npm, or bun package installation processes modify the Claude AI settings.json file. This could indicate potential supply chain compromise or unauthorized configuration changes to the Claude application environment via malicious packages or scripts.
avatar
Hrushikesh Badgujar@H3AD
XQL - Cortex Detections
24 days ago
101
Detects PEEP Secure Preferences integrity-hash forgery (protection.macs/super_mac) and known PEEP persistence scripts (patch_secure_prefs.ps1, install_silent.ps1, force_enable.ps1), anchored to actual Chrome/Edge profile paths rather than generic terms like 'protection' or 'developer_mode' that appear in unrelated admin tooling.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
28 days ago
404
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
004
Detects outbound network connections to 'registry.npmjs.org' originating from 'node' or 'bun' processes. This behavior may indicate an attempt to exfiltrate data, interact with malicious packages, or perform credential harvesting via npm tokens during execution.
avatar
Hrushikesh Badgujar@H3AD
avatar
Detections.ai Community
24 days ago
101
Detects outbound network connections to 'registry.npmjs.org' originating from 'node' or 'bun' processes. This behavior may indicate an attempt to exfiltrate data, interact with malicious packages, or perform credential harvesting via npm tokens during execution.
avatar
Hrushikesh Badgujar@H3AD
XQL - Cortex Detections
24 days ago
101
This rule identifies potential command-and-control (C2) beaconing behavior by detecting repetitive, consistent connections (low jitter) to public IP addresses over common TLS ports (443, 8443, 4443, 9443) from processes that do not have a known history of connecting to those destinations. It establishes a baseline of historical connections to filter out legitimate traffic and uses a statistical analysis of connection intervals to highlight suspicious, non-human-like automated communication patterns.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
21 days ago
000
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
This rule detects potential Command and Control (C2) beaconing activity by identifying periodic outbound network connections from suspicious or non-browser processes. It analyzes the time deltas between successful network connections; if the standard deviation of these intervals is low (indicating consistent timing) and a sufficient number of connections occur, it flags the behavior as a potential C2 heartbeat.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
22028
Detects suspicious DLL loads or file drops performed by security product processes (avp.exe, MsMpEng.exe) from directories outside of standard, trusted vendor paths. It specifically flags unsigned or invalidly signed DLLs, which is indicative of DLL sideloading techniques used to abuse security software workflows for potential privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
8014
Detects the execution of command-line shells (cmd, powershell, pwsh) running under the SYSTEM context that were initiated by or associated with a process containing 'ShieldBreak' in its filename. This behavior is indicative of a suspicious or potentially malicious process (e.g., a security bypass tool) attempting to spawn elevated shells.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
13018
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
avatar
Arnold Chan@slaz
Defender - KQL
26 days ago
102