Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects a sequence of multiple process injection-related API calls (VirtualAlloc, WriteProcessMemory, CreateRemoteThread) initiated by a process. This rule monitors for patterns indicating cross-process memory manipulation which is commonly used to inject malicious code into other processes. It specifically looks for API calls interacting with kernel32.dll and filters out known Microsoft security products.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
005
Detects a dual persistence mechanism where an adversary establishes both an identically-named Registry Run key and a Scheduled Task, both masquerading as legitimate Canon or Stardock configuration software. These artifacts are configured to launch side-loaded host binaries (COTFileReadApp.exe or DeElevate64.exe) to maintain persistence on a Windows host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects a loader module and a corresponding RIFF/WAVE file that utilizes steganography to conceal a secondary malicious payload. The loader extracts the payload from the WAV file using specific offsets and XOR decoding, then executes it in memory. This pattern is characteristic of a DLL sideloading chain involving WMPCL.dll and WPFLocalizeExtension.dll.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of PowerShell scripts that utilize large arrays of negative integers to reconstruct and dynamically execute code via the [scriptblock]::Create method. This technique is commonly used to obfuscate malicious payloads such as downloaders or API calls from static analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects a sequence of distinct system and network reconnaissance commands typically performed by malware or RATs for environment fingerprinting. The rule triggers when three or more unique reconnaissance activities—such as querying antivirus status, enumerating network adapters, checking domain information, or listing installed software—occur from the same host within a 5-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects malicious DLLs identified by specific exports and imports (e.g., rdCore.dll, I++u.dll) that are intended to be sideloaded by signed binaries such as Canon's COTFileReadApp.exe or Stardock software. The detection relies on identifying the combination of sideloaded component names and the presence of suspicious import structures characteristic of these specific staging loaders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects instances where the GOMCam2024 executable launches or spawns a Chrome process with specific command-line arguments involving the user-data-directory being set to the system Temp folder. This behavior is often indicative of process injection, proxy-based credential theft, or attempts to execute browser sessions in a non-standard, potentially malicious context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the creation of a Windows scheduled task using 'schtasks.exe' or the system's scheduled task creation event where the command line or task details contain the string 'psychedelicloveUtils'. This pattern is often indicative of specific malicious persistence mechanisms or automated task-based payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
This rule detects the creation or modification of browser native messaging host configuration files (e.g., com.lunex.explorer.json) combined with the simultaneous or subsequent termination of common web browsers. This pattern is indicative of potential browser hijacking, where an adversary sets up a malicious native messaging host to facilitate persistence or intercept browser communications and subsequently restarts or terminates the browser process to reload the configuration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of msiexec.exe to install an MSI package from a remote URL. This pattern involves the Windows Installer utility being invoked by explorer.exe with the /i (install) and /passive (unattended installation) flags, indicating a potentially malicious download and execution chain often used to deliver payloads via social engineering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the exploitation of the CMSTPLUA COM-object (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7) to bypass User Account Control (UAC). The rule monitors for PowerShell processes instantiating this object, followed by the execution of a hidden-window PowerShell process, bypassing the consent.exe UAC prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
This rule detects a multi-tool attack chain involving the Cairn autonomous exploitation engine and the Hermes Agent. It flags the co-occurrence of outbound network traffic to both the DeepSeek API (Cairn engine) and the Anthropic Claude API (Hermes Agent) from the same host within a one-hour window. This behavior is indicative of an automated, AI-driven post-exploitation orchestration campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects an endpoint initiating outbound network connections to three or more distinct LLM provider APIs (DeepSeek, Qwen, Mistral, Gemini) within a short timeframe (15-minute windows). This behavior aligns with the multi-provider voting mechanism used by the CLOSEDQUORUM post-compromise framework to autonomously determine subsequent actions using diverse generative AI models.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects a suspected automated exploitation sequence where a web storefront file (e.g., .phtml, .js, .php) is modified to inject malicious script code (skimmer), followed by an unauthorized SQL DELETE operation on sensitive database tables containing payment, customer, or order information, originating from the same host within a 6-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects evidence of the CARBONATO post-exploitation pattern, specifically identifying the installation of a Hermes Agent by monitoring the creation of a 'SOUL.md' persona file within a '.hermes' folder, followed by correlated outbound network traffic to a specific LLM gateway or known Vercel proxy infrastructure used for command relay.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects a specific command and control (C2) communication pattern characteristic of RatHat malware, involving the retrieval of HTML overlay templates followed by the submission of captured form or credential data from the same device within a one-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects instances where a Node.js process (node.exe) initiates command-line interpreters (cmd.exe, powershell.exe) with specific arguments or command lines associated with administrative or potentially obfuscated/automated script execution. This is a common pattern for post-exploitation activities or legitimate administrative automation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the presence of Node.js runtime files (node.exe, index.js) or script-based agents (vbs, ps1) located within user-profile paths (AppData) that mimic legitimate Windows system folders. This pattern is characteristic of masquerading techniques used to stage or run malicious agents under the guise of system components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the compilation of a Managed Object Format (MOF) file using mofcomp.exe from the temporary directory of the MSSQL service account. This behavior is indicative of an attacker leveraging the xp_cmdshell procedure in MSSQL to deploy a malicious MOF file, which registers a WMI permanent event subscription to establish persistence or facilitate secondary payload execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects a successful authentication to Microsoft SQL Server using the 'sa' account from a non-local address. This rule is designed to alert on potentially unauthorized access following a brute-force attack, as identified by the correlation of high-volume authentication failures (Event ID 18456) followed by a successful login (Event ID 18453/18454).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the modification of the Image File Execution Options (IFEO) registry key for 'smss.exe' to set a Debugger value. This technique is often used for persistence, whereby an adversary redirects the execution of a legitimate system process to a malicious executable (e.g., a renamed binary like svchost.exe located outside of System32).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Page 119 of 1870