Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
004
Detects HTTP GET requests originating from internal hosts to external destinations where the User-Agent string contains 'AutoIt'. This behavior is indicative of the DarkGate malware downloading additional payloads or components using AutoIt scripting capabilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
405
Detects the installation of a specific known malicious npm package named 'tw-pkgprobe-7731' via the command line, which may indicate a supply chain compromise or an attempt to execute malicious code within a development environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
502
Detects Node.js processes establishing network connections to common webhook relay and collection services, which may indicate data exfiltration or credential theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
002
Detects DNS queries for the domain 'pdf.gusercontent.com', which is known to be used as a lookalike domain for Google-related services to deceive users. This pattern is often indicative of malicious infrastructure used for credential harvesting, phishing, or malware delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
002
Detects unauthorized outbound network traffic from browser processes to the lookalike domain 'pdf.gusercontent.com'. This domain is associated with a malicious Firefox browser extension, 'PDF Identity Verifier', which is designed to exfiltrate session telemetry and data from Google account sessions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
002
Detects the execution of PowerShell scripts located in Windows temporary directories (AppData/Local/Temp or Temp) that utilize common evasion flags such as hidden window style, bypass execution policy, or non-interactive mode. This behavior is frequently associated with initial stagers, droppers, or malicious script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
105
This rule detects PowerShell commands that attempt to reassemble a Base64-encoded payload from multiple concatenated variable fragments. It specifically looks for patterns where filler characters ('*' or '?') are stripped from the payload before it is passed to the [Convert]::FromBase64String method. This technique is commonly used to evade static string analysis and signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
205
Detects the Windows Character Map utility (charmap.exe) loading suspicious modules such as amsi.dll or clr.dll followed by a process execution involving PowerShell or an unidentified command string, which is indicative of DLL side-loading or process hollowing techniques for malicious code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
105
Detects the execution of PowerShell with encoded commands that explicitly perform base64 string decoding using 'FromBase64String'. This pattern is frequently used to obfuscate scripts or payloads, often seen in downloader stagers or malicious scripts to bypass security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
Detects modifications to Windows Registry Run and RunOnce keys by processes other than standard system binaries and known management tools. Such modifications are a common method for achieving persistence by ensuring malicious code executes upon user logon.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
Detects execution of rundll32.exe from non-standard locations or utilizing specific exported DLL functions often associated with bypassing application whitelisting, executing scripts, or proxying malicious code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
Detects the use of PowerShell to modify Windows Defender configuration settings, specifically targeting the disabling of real-time monitoring, behavioral monitoring, or other security protections via the Set-MpPreference cmdlet.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
Detects the creation of scheduled tasks using schtasks.exe or PowerShell where the task binary path resides in suspicious directories frequently used by adversaries for staging, such as AppData, Temp, Downloads, or Public folders.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
This rule detects a malicious execution chain starting with an MSI file being launched by explorer.exe from user-downloaded folders. The installer spawns chrome.exe, drops a specific loader file (e.g., PavokwiLoader.exe or Loader.exe) into the %LOCALAPPDATA%\Temp\modules\ directory, and establishes persistence via the HKCU 'Load' registry value pointing to that location.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
Detects a sequence of multiple process injection-related API calls (VirtualAlloc, WriteProcessMemory, CreateRemoteThread) initiated by a process. This rule monitors for patterns indicating cross-process memory manipulation which is commonly used to inject malicious code into other processes. It specifically looks for API calls interacting with kernel32.dll and filters out known Microsoft security products.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
005
Detects a dual persistence mechanism where an adversary establishes both an identically-named Registry Run key and a Scheduled Task, both masquerading as legitimate Canon or Stardock configuration software. These artifacts are configured to launch side-loaded host binaries (COTFileReadApp.exe or DeElevate64.exe) to maintain persistence on a Windows host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects a loader module and a corresponding RIFF/WAVE file that utilizes steganography to conceal a secondary malicious payload. The loader extracts the payload from the WAV file using specific offsets and XOR decoding, then executes it in memory. This pattern is characteristic of a DLL sideloading chain involving WMPCL.dll and WPFLocalizeExtension.dll.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of PowerShell scripts that utilize large arrays of negative integers to reconstruct and dynamically execute code via the [scriptblock]::Create method. This technique is commonly used to obfuscate malicious payloads such as downloaders or API calls from static analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Page 118 of 1870