Curated detection query library across KQL, Sigma, and XQL. Filter by format, tactic, or technique. Copy queries directly for use in your SIEM.
10 queries loaded
Detects PowerShell processes launched with encoded commands or suspicious parameters, common in initial access and execution phases.
Detects Microsoft Office applications making unexpected outbound network connections, often indicative of macro-based C2 callbacks.
Detects modifications to registry Run keys, a common persistence mechanism used by malware to establish foothold.
Detects processes attempting to access LSASS memory for credential dumping via tools like Mimikatz or ProcDump.
Detects creation of scheduled tasks on remote hosts, commonly used for lateral movement and persistence.
Detects processes attempting to terminate or disable security software, a common defense evasion technique.
Detects processes creating remote threads in another process, a common code injection technique.
Detects RDP connections from unusual source IPs or geographies, indicative of lateral movement or external compromise.
Detects creation of archive files in unusual locations or volumes, often preceding exfiltration.
Detects services installed from non-system32 paths, a common evasion technique for establishing persistence.
H3AD-DETECT / TRACERULES · 10 rules · KQL · Sigma · XQL
JavaScript Required
This portfolio website requires JavaScript to display properly. Please enable JavaScript in your browser settings, or contact me directly at hello@pranithjain.qzz.io.