Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

This rule detects scenarios where a node-based package manager (npm or npx) executes an 'install' command, which is immediately followed by the spawning of unexpected child processes such as interpreters (python, powershell, cmd, wscript, cscript, mshta) or network tools (curl). This behavior is characteristic of malicious npm packages used in supply chain attacks to deliver secondary payloads like BeaverTail, InvisibleFerret, or similar threats.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
206
Detects reconnaissance and situational-awareness collection commands (e.g., tasklist, systeminfo, wmic, powershell) executed by processes matching suspected persistence artifacts associated with known malicious activity (specifically referencing potential Telegram C2 tasking). The rule monitors common discovery utilities spawned by suspicious process names or paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
006
This rule detects the creation of a file within the SysWOW64 directory followed by an immediate modification or creation of a Windows Run registry key within a 10-minute window. This behavior is indicative of a persistence mechanism where a malicious file is dropped to a system directory and registered for execution at system startup or user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
106
Detects a coordinated malicious installation chain involving the creation of specific mutexes, establishment of persistence via Windows Registry Run keys, and subsequent tampering with Microsoft Defender exclusions using PowerShell. This sequence is indicative of the CHOSEN BRICK malware installation process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
006
Detects execution of the CHOSEN BRICK implant (process names smdqservice.exe or winappx.exe) initiating a network connection to Telegram infrastructure (C2) followed by a network connection to a cloud object-storage provider (vultrobjects.com, storjshare.io, or backblazeb2.com) for data exfiltration within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
006
Detects instances where a non-browser process initiates network connections to multiple AI service providers and Discord within a 15-minute correlation window, potentially indicating automated data exfiltration or unauthorized interaction with AI platforms using tools other than standard web browsers.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
11 days ago
003
Detects instances where a non-browser process initiates network connections to multiple AI service providers and Discord within a 15-minute correlation window, potentially indicating automated data exfiltration or unauthorized interaction with AI platforms using tools other than standard web browsers.
avatar
Goksel Atakan@gokselatakan
Defender - KQL
11 days ago
403
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
9023
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
506
Detects unauthorized processes attempting to access the cloud instance metadata service (169.254.169.254). Adversaries frequently target this endpoint to extract sensitive instance information, such as IAM credentials or configuration data, typically as part of post-exploitation discovery or SSRF-based attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects instances where AI agent host processes (such as Python, .NET, or IIS worker processes) spawn suspicious child processes like command interpreters or common system utilities. This behavior is indicative of potential Remote Code Execution (RCE) via prompt injection, where an AI agent is manipulated into executing arbitrary system commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
003
Detects the suspicious retrieval and immediate execution of Agentic AI configuration files (e.g., AGENTS.md, KNOWLEDGE.md) from remote sources using common command-line utilities. This pattern is indicative of an adversary injecting malicious agent instructions or unauthorized configurations into an AI environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
603
Detects incoming web requests containing a 'pagename' parameter with URL-encoded path traversal sequences, which could allow unauthorized file access or directory traversal attacks against WordPress page-template resolution as described in CVE-2026-87902.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
003
This rule detects unauthorized attempts to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. It monitors for common post-exploitation tools (such as procdump, mimikatz, nanodump, and sqldumper) or built-in Windows techniques (using rundll32.exe with comsvcs.dll) that are typically used to extract sensitive credential material from process memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the WMI provider host (wmiprvse.exe) spawning common living-off-the-land binaries often associated with command execution or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous patterns of Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting attacks. The rule identifies accounts requesting a high volume of service tickets for distinct Service Principal Names (SPNs), excluding the krbtgt account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of known Windows 'Living-off-the-Land' binaries (rundll32.exe, regsvr32.exe, mshta.exe) when they originate from web browsers or office productivity applications, or when they are executed with command-line arguments indicative of network resource loading, remote scripting, or code execution bypasses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000