Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

This rule detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to perform actions associated with ransomware, such as deleting volume shadow copies, deleting the backup catalog, or disabling system recovery features. This is a common precursor to data encryption to prevent the user from restoring files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous Kerberos TGS ticket requests (Event ID 4769) where a single user requests tickets for multiple distinct Service Principal Names (SPNs) using weak RC4 (0x17) encryption. This behavior is highly characteristic of Kerberoasting, a technique used by adversaries to harvest service account tickets for offline cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the abuse of signed Windows system binaries (LOLBins: certutil, mshta, regsvr32, rundll32, bitsadmin, msiexec) through the identification of command-line arguments that suggest malicious activity, such as downloading remote content, decoding files, executing scriptlets, or loading DLLs from temporary storage directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell. The rule looks for command-line arguments referencing AMSI-related memory structures, methods, and DLLs such as AmsiUtils, AmsiScanBuffer, AmsiInitFailed, and amsi.dll. Bypassing AMSI is a common technique used by attackers to execute malicious scripts and deploy fileless payloads, such as Cobalt Strike or Sliver, while avoiding detection by endpoint security solutions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential Golden SAML activity by correlating Azure AD SAML sign-in events for privileged accounts with a lack of corresponding server-side ADFS authentication logs, unusual SAML issuer URIs, lack of on-premises authentication logs, or evidence of direct access to ADFS token-signing certificate private key material.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of native Windows utilities such as vssadmin, wmic, wbadmin, and bcdedit used to delete volume shadow copies, the backup catalog, or disable system recovery boot policies. This activity is a common precursor to ransomware encryption to prevent data restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of token manipulation APIs (DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser), the 'runas' command for credential switching, or the execution of known security token manipulation tools (e.g., incognito, Tokenvator, Invoke-TokenManipulation). This activity is commonly associated with privilege escalation and token theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of data archival utilities (7zip, WinRAR) or command-line cloud synchronization tools (Rclone) to stage files in common temporary directories, immediately followed by network connections to known cloud storage endpoints. This pattern is characteristic of pre-encryption exfiltration activities often seen in ransomware campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects legitimate, signed executables from trusted system locations (e.g., System32) loading DLLs from non-standard, user-writable directories (e.g., Temp, AppData). This activity is a classic indicator of DLL side-loading, where an adversary places a malicious DLL in a directory to be picked up by a legitimate application, enabling the execution of malicious code under the context of a trusted process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects suspicious cross-process memory operations where a source process requests process creation/write permissions on a target process (e.g., browsers, explorer.exe, or svchost.exe), followed immediately by the execution of a remote thread injection technique such as CreateRemoteThread, QueueUserAPC, or NtCreateThreadEx within the same process pair.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects multiple attempts to connect to administrative shares (ADMIN$, C$, IPC$) from a single source within a 60-second window. This pattern is indicative of automated lateral movement or enumeration attempts using the SMB protocol.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
104
Detects the use of the built-in Windows utility rundll32.exe to execute the MiniDump functionality within comsvcs.dll against the Local Security Authority Subsystem Service (LSASS). This technique is a common method for attackers to bypass signature-based security tools and obtain sensitive credentials from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
604
Detects the abuse of the legitimate Windows system binaries regsvr32.exe and rundll32.exe to execute remote scripts or scriptlets, a technique often used to bypass application control and proxy execution of malicious code (similar to Squiblydoo).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of reg.exe with the 'save' command to extract the SAM, SYSTEM, or SECURITY registry hives to disk. This technique is commonly used by attackers to offline extract credential hashes, facilitating pass-the-hash attacks and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
004
Detects the execution of PowerShell with encoded commands (e.g., -EncodedCommand or -enc) combined with common download cradle indicators such as IEX, Net.WebClient, or DownloadString. This combination is highly indicative of fileless malware execution, initial access payload staging, or defense evasion techniques often employed by threat actors to bypass command-line monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized directory replication requests (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) made against Active Directory by a user or computer account that is not a domain controller. This behavior is indicative of a DCSync attack, typically performed by tools like Mimikatz to extract password hashes for all domain accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the task is configured to run in the security context of the SYSTEM account or executes suspicious binaries like PowerShell, mshta, or other living-off-the-land binaries. This behavior is indicative of potential persistence mechanisms employed by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the abuse of the built-in Windows utility 'certutil.exe' to download remote files using URL cache functionality or to deobfuscate base64-encoded payloads. This is a common LOLBin (Living-off-the-Land Binary) technique used in phishing loaders, malware delivery, and post-exploitation toolkits.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000