Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

Detects the request for DS-Replication-Get-Changes or DS-Replication-Get-Changes-All extended rights on domain objects, which are highly sensitive Active Directory permissions required to perform DCSync attacks to harvest credentials from Domain Controllers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized modifications to Windows Registry Run/RunOnce keys or the Startup folder. The rule specifically targets persistence attempts where the associated process resides in suspicious directories (Temp, AppData) or uses command-line arguments indicative of script execution (powershell, wscript, mshta, encoded commands, or script extensions). It excludes known legitimate installer behavior involving msiexec or setup processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects WmiPrvSE.exe spawning child processes within 120 seconds of a Type 3 (Network) logon event. This behavior is a common indicator of remote command execution, frequently used by lateral movement tools like Impacket's wmiexec or similar WMI-based remote execution frameworks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests using the weak RC4 encryption type (0x17) from a single account within a 5-minute window. It excludes machine accounts and common system service requests to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects suspicious NTLM network logon events (Logon Type 3) involving privileged accounts that do not have corresponding Kerberos authentication events (4768/4769) in the preceding hour. The detection specifically triggers when a single account logs into two or more distinct hosts within a 15-minute window, which is indicative of lateral movement using compromised credentials or Pass-the-Hash techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using Event ID 4698 or command-line execution of schtasks.exe. The rule specifically looks for tasks created in suspicious paths such as AppData or ProgramData, or tasks configured to run with highest privileges and/or marked as hidden, which are common indicators of persistence mechanisms used by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous Kerberos service ticket (TGS) requests or successful logons where the corresponding Ticket Granting Ticket (TGT) request (Event ID 4768) is absent within the monitored window. This pattern is a primary indicator of offline-forged Kerberos tickets, such as those generated by Mimikatz, which bypass legitimate KDC interaction for ticket issuance.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks (via Event ID 4698 or schtasks.exe) involving suspicious action paths, encoded PowerShell commands, LOLBins, or tasks configured to run as SYSTEM by non-administrator users, which is a common persistence mechanism for malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using Event ID 4698 or command-line execution of schtasks.exe. The rule specifically looks for tasks created in suspicious paths such as AppData or ProgramData, or tasks configured to run with highest privileges and/or marked as hidden, which are common indicators of persistence mechanisms used by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous Kerberos service ticket (TGS) requests or successful logons where the corresponding Ticket Granting Ticket (TGT) request (Event ID 4768) is absent within the monitored window. This pattern is a primary indicator of offline-forged Kerberos tickets, such as those generated by Mimikatz, which bypass legitimate KDC interaction for ticket issuance.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the suspicious execution of rundll32.exe or regsvr32.exe, which are commonly abused as Living-off-the-Land Binaries (LOLBins). It identifies potential malicious activity by analyzing command-line arguments for patterns like remote URL requests, usage of scrobj.dll, JavaScript protocols, or specific Squiblydoo attack patterns. Additionally, it monitors for these binaries being executed by parents other than explorer.exe, which is indicative of potential process injection or proxy execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects attempts to access or dump the memory of the Local Security Authority Subsystem Service (LSASS) process, a technique commonly used by adversaries to harvest domain credentials and clear-text passwords from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects lateral movement techniques leveraging Windows Management Instrumentation (WMI). The rule identifies instances where the WMI provider host, WmiPrvSE.exe, spawns common administrative or interactive shell tools (e.g., cmd.exe, powershell.exe). This pattern is consistent with the abuse of Win32_Process.Create() via WMI/DCOM/RPC for remote command execution, a method frequently utilized by frameworks like Impacket (wmiexec.py) for fileless, agentless lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential RDP brute force and password spraying attacks by correlating Windows Event ID 4625 (failed logins) and 4624 (successful logins) via RDP (Logon Type 10). It monitors for high volumes of failed attempts across multiple accounts or high volume of failed attempts from a single source, followed by successful authentication from the same source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized usage of the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, which are required for the DCSync technique. The rule monitors for Windows Event ID 4662 (Object Access) where a non-domain controller account attempts these replication operations, typically indicative of credential dumping and domain compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (LSASS) process with access rights consistent with credential dumping (e.g., PROCESS_VM_READ, PROCESS_ALL_ACCESS). This rule also specifically flags the use of well-known tools and techniques such as Mimikatz, ProcDump, and the abuse of rundll32.exe with comsvcs.dll for memory extraction, which is indicative of OS Credential Dumping (T1003.001).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects persistence mechanisms by monitoring additions to Windows Registry Run keys or files created in the user's Startup directory. It specifically flags entries that target suspicious locations (e.g., Temp, AppData, Public) or attempt to execute encoded commands using PowerShell or CMD.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential lateral movement indicative of PsExec or similar administrative tools. It identifies the combination of remote service installation (often using ADMIN$ or Temp paths), access to administrative shares (ADMIN$ or C$), and the execution of a process spawned by services.exe, which is characteristic of the remote service control manager performing remote service starts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to perform actions associated with ransomware, such as deleting volume shadow copies, deleting the backup catalog, or disabling system recovery features. This is a common precursor to data encryption to prevent the user from restoring files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) where a single user requests tickets for multiple distinct Service Principal Names (SPNs) using weak RC4 (0x17) encryption. This behavior is highly characteristic of Kerberoasting, a technique used by adversaries to harvest service account tickets for offline cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000