Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects files matching known SHA256 hashes of the masqueraded MSP360 RMM v2.5.0.67 installer and associated ScreenConnect/utility payloads used in phishing-to-dual-RMM campaigns
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects files matching known SHA256 hashes of the masqueraded MSP360 RMM v2.5.0.67 installer and associated ScreenConnect/utility payloads used in phishing-to-dual-RMM campaigns
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects files matching known SHA256 hashes of the masqueraded MSP360 RMM v2.5.0.67 installer and associated ScreenConnect/utility payloads used in phishing-to-dual-RMM campaigns
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects instances where the Faronics Deploy Agent process initiates the installation or download of ScreenConnect remote access software via PowerShell or the Windows Installer (msiexec.exe). This pattern is often indicative of authorized RMM deployment, but it is also a common tactic for adversaries to establish persistent remote access to endpoints.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects instances where the Faronics Deploy Agent process initiates the installation or download of ScreenConnect remote access software via PowerShell or the Windows Installer (msiexec.exe). This pattern is often indicative of authorized RMM deployment, but it is also a common tactic for adversaries to establish persistent remote access to endpoints.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects instances where the Faronics Deploy Agent process initiates the installation or download of ScreenConnect remote access software via PowerShell or the Windows Installer (msiexec.exe). This pattern is often indicative of authorized RMM deployment, but it is also a common tactic for adversaries to establish persistent remote access to endpoints.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects the execution of known browser credential harvesting tools (WebBrowserPassView, WebBrowserBookmarksView, or WS_Password variants) from ScreenConnect temporary directories. This behavior often indicates post-compromise activity where an adversary uses an existing Remote Monitoring and Management (RMM) session to extract credentials from browsers.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the execution of known browser credential harvesting tools (WebBrowserPassView, WebBrowserBookmarksView, or WS_Password variants) from ScreenConnect temporary directories. This behavior often indicates post-compromise activity where an adversary uses an existing Remote Monitoring and Management (RMM) session to extract credentials from browsers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects the execution of known browser credential harvesting tools (WebBrowserPassView, WebBrowserBookmarksView, or WS_Password variants) from ScreenConnect temporary directories. This behavior often indicates post-compromise activity where an adversary uses an existing Remote Monitoring and Management (RMM) session to extract credentials from browsers.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
001
Page 104 of 1870