DIR: ~/detections
Detections_
Detection queries for SIEM and SOAR platforms. SPL, KQL, EQL and more.
C2 Beacon Detection via DNS Regularity
Elastic SIEMIdentifies potential command-and-control beaconing behaviour by analysing the statistical regularity of DNS queries to external domains from internal hosts.
c2dnsbeaconing
Lateral Movement via PsExec
Microsoft SentinelDetects use of PsExec or similar remote execution tools for lateral movement, based on characteristic service creation events and named pipe patterns.
lateral-movementpsexecwindows
Brute Force Login Detection
SplunkDetects repeated failed authentication attempts against a single account within a short time window, indicative of password brute-forcing activity.
authenticationbrute-forcecredential-attack