Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
001
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
001
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
001
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
001
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
001
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
001
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
001
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
001
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
101
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
001
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
106
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
006
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
003
Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
606
This rule detects unauthorized or anomalous file modifications or creations to machine learning training datasets (e.g., fine-tuning data, training corpora) by users not belonging to the authorized data engineering group, occurring within one hour of a scheduled training or fine-tuning job execution. This behavioral pattern is indicative of potential data poisoning, where an adversary attempts to inject malicious data into the training set to bias or compromise the resulting model.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects network connection events associated with the download of machine learning model artifacts from public hubs that display indicators of malicious intent, such as unverified or newly created publisher accounts, missing or invalid cryptographic signatures, or the presence of embedded executable/pickle-deserialization payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects network connection events associated with the download of machine learning model artifacts from public hubs that display indicators of malicious intent, such as unverified or newly created publisher accounts, missing or invalid cryptographic signatures, or the presence of embedded executable/pickle-deserialization payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Page 105 of 1870