Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

Detects anomalous lateral movement behavior by monitoring Windows Event 4624 (Logon Type 3) using NTLM authentication. The rule triggers when a single user account authenticates to five or more distinct hosts within a five-minute window, a pattern frequently associated with Pass-the-Hash attacks where captured credentials are used to spread across a network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects non-SYSTEM processes enabling SeDebugPrivilege or SeImpersonatePrivilege shortly before launching a process as the SYSTEM user. This behavior is highly indicative of token manipulation and impersonation techniques (e.g., Potato-family exploits) used to elevate privileges from a standard or administrative account to SYSTEM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects attempts to disable security services (Windows Defender, EDR agents), modify audit policies via auditpol, or stop/clear the Windows Event Log service. This behavior is a common precursor to post-compromise activity intended to blind defenders and conceal malicious actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects an attempt to perform Active Directory replication (DS-Replication-Get-Changes or DS-Replication-Get-Changes-All) initiated by a machine that is not a recognized Domain Controller. This is a common indicator of credential dumping or unauthorized domain information gathering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
000
This rule detects the creation of scheduled tasks using either 'schtasks.exe' or PowerShell ('powershell.exe', 'pwsh.exe') with suspicious parameters. It flags tasks created in temporary directories (e.g., AppData, Temp, ProgramData, Windows\Temp) or tasks executed with 'highest' privileges or hidden configurations, often used for persistence or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the 'ClickFix' attack pattern where explorer.exe (typically via a Run dialog interaction) spawns a command shell (PowerShell, cmd, or mshta) using obfuscated flags combined with execution indicators (download/execution), which then subsequently spawns a secondary child process. This chain provides high-confidence evidence of malicious intent compared to isolated process executions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
000
Detects attempts to dump credentials from the Local Security Authority Subsystem Service (LSASS) process memory using common tools like Mimikatz, Procdump, or built-in system utilities such as comsvcs.dll or command-line arguments indicating memory dump operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos TGS requests (Event ID 4769) for tickets encrypted with RC4 (0x17) within a short timeframe. The rule tracks the count of requests and the diversity of Service Principal Names (SPNs) requested by a specific user account, excluding machine accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential persistence mechanisms on Windows systems by monitoring for the creation or modification of Registry 'Run' or 'RunOnce' keys, as well as the creation of files within the Windows Startup folder. These actions are commonly used by adversaries to ensure malicious code executes automatically upon user login or system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects execution of regsvr32.exe with command-line arguments that include a remote URL ('/i:http...') combined with silent, unregistered, and notification-free execution flags ('/s', '/u', '/n'). This behavior is characteristic of the 'Squiblydoo' technique, where attackers use Regsvr32 to execute arbitrary scriptlets from remote servers to bypass application whitelisting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances of rundll32.exe being used with suspicious command line arguments, such as referencing JavaScript, loading Control Panel applets (.cpl) via shell32.dll from non-standard locations, or executing DLLs directly from user-writable directories (Temp, AppData, Downloads, ProgramData). These patterns are common techniques used by adversaries to proxy execution and evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential lateral movement and persistence activities by identifying suspicious Windows service installations via event ID 7045. The rule flags services with suspicious names or paths (e.g., Temp folders, Public directory) and correlates them with incoming SMB connections (port 445) or services spawned directly by services.exe from suspicious locations, aggregated by host and remote IP.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the execution of the Microsoft HTML Application host (mshta.exe) when it is used to launch scripts from remote URLs (http/https/ftp) or when it spawns common command-line shells and scripting engines, which is a common indicator of living-off-the-land techniques used to execute malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects various forms of process injection (Remote Thread, APC, Map View of Section) targeting common, high-value Windows processes such as explorer.exe, lsass.exe, and web browsers. This behavior is a common technique used by attackers to gain persistence, elevate privileges, or execute code within the context of legitimate system or user-level processes to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized attempts by processes to access the memory of sensitive Windows system processes, specifically LSASS.exe or winlogon.exe, using suspicious access masks associated with memory dumping or credential harvesting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects DCSync attacks by monitoring for EventID 4662 where Active Directory replication extended rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) are requested. This behavior is indicative of unauthorized replication attempts used to extract sensitive data, such as password hashes, directly from a Domain Controller.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the abuse of signed Windows system binaries regsvr32.exe and rundll32.exe for proxy execution, defense evasion, and credential access. The rule identifies suspicious command-line patterns including Squiblydoo (regsvr32 with remote scriptlets), rundll32 executing JavaScript via mshtml.dll, rundll32 performing LSASS credential dumping via comsvcs.dll, and the loading of DLLs from untrusted user-writable locations like Temp or Downloads folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects Kerberos service ticket requests (EventID 4769) that utilize RC4 encryption (0x17) instead of the more secure AES encryption. Attackers often force RC4-HMAC when requesting service tickets for accounts with Service Principal Names (SPNs) because these tickets are susceptible to offline brute-force attacks to recover service account passwords. This technique is a common precursor to lateral movement and privilege escalation in Active Directory environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000