Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the creation of a local administrative account with a hidden naming convention (ending in $) accompanied by a cluster of registry modifications designed to obscure the account from the logon screen, enable WDigest plaintext credential caching, relax RDP authentication requirements (disable NLA, enable RDP), and disable UAC remote restrictions. This activity is highly indicative of post-exploitation persistence and credential harvesting configurations following initial access via SQL server exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects a UAC bypass sequence associated with the ChainScript/Rapuncel loader, where a process invokes an 'elevation:Administrator!new' COM moniker (such as CMSTPLUA or ICMLuaUtil) followed by the execution or hollowed-out spawning of 'ServiceModelReg.exe' to achieve elevated privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects execution of an XMRig cryptominer masquerading as the legitimate system process 'smss.exe' from a non-standard file path. This detection specifically identifies the presence of the WinRing0x64.sys kernel driver, often used by XMRig for hardware MSR access, and detects preceding malicious activity involving UnRAR extraction of the miner using a specific password.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects anomalous file staging activity combined with keyword-matched file access or suspicious Steam application launches, characteristic of the Rapuncel (BoryptGrab) malware's credential and crypto-wallet harvesting routine.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
104
Detects instances where the Node.js runtime process (node.exe) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently used by malicious Node.js-based applications, RATs, or web shells to execute arbitrary commands on a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects instances where the Node.js runtime process (node.exe) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently used by malicious Node.js-based applications, RATs, or web shells to execute arbitrary commands on a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the NeedyMantis second-stage loader, typically encountered as a malicious script (e.g., encryptbase64.ps1). The detection identifies raw shellcode residing in files that exhibit specific traits: PEB-walking for API resolution using a ROR(11) hashing algorithm, the inclusion of the 'RtlDecompressBuffer' API for payload expansion, and the absence of standard PowerShell script headers at the start of the file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects evidence of the Rapuncel infostealer attempting to compromise Chrome or Edge browsers. The rule identifies suspicious image loads into browser processes linked to known malicious hashes or the creation of specific browser decryption log files used by the malware to defeat App-Bound encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects NeedyMantis malware loader components that utilize the RtlDecompressBuffer API for custom XOR-compressed archive extraction. The rule specifically looks for the presence of known staged file names (dnsapi.dll, ws2_32.dll, msvcrt140.dll, or encryptbase64.ps1) alongside decoy file references typically used by the threat actor.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the NeedyMantis malware component loading configuration and communications modules (specifically dnsapi.dll or ws2_32.dll) from a non-standard system directory. This behavior is indicative of DLL hijacking or side-loading, where a malicious library is substituted for a legitimate Windows system library to facilitate command and control or malicious execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects persistence mechanisms associated with 'ComponentTask33Agent' which involves either creating a scheduled task or modifying Windows Registry Run keys, alongside potential VBScript-based agent execution via wscript.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the creation of Windows services by known binary hosts frequently utilized by NeedyMantis for DLL sideloading. This activity is indicative of the persistence phase where the actor's 'is' module registers itself as a service to ensure survival across system reboots following the execution of the sideloading chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects a specific privilege escalation and code execution chain attributed to the PUROSANGUE methodology. This activity involves using a COM Elevation Moniker (specifically with the 'Elevation:Administrator!new:' syntax) to bypass UAC, followed by process hollowing into ServiceModelReg.exe. The attack is initiated from unconventional parent processes such as vsdbg.exe or its associated DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects NeedyMantis first-stage loader activity where a legitimate application (e.g., Poedit, curl, Vim, TightVNC) is executed to load an update or support DLL from a non-standard staging path (e.g., %ProgramData% subdirectories), followed by the presence of a co-located encrypted second-stage archive.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the ChainScript RAT, executing via a masqueraded Node.js process, enumerating Local Extension Settings for browser wallet plugins. This reconnaissance activity is a precursor to exfiltrating crypto wallet data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the spawning of script interpreters or loaders by Visual Studio Code (Code.exe) shortly after a workspace is initialized, specifically looking for command-line arguments referencing .vscode or tasks.json. This behavior is consistent with exploitation techniques where a user accepts a 'Trust Workspace' prompt, allowing malicious tasks defined in a repository's .vscode folder to execute.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects specific malicious archive payloads associated with NeedyMantis that contain a second-stage loader and spoofed system DLLs (e.g., dnsapi.dll, ws2_32.dll, msvcrt140.dll). These archives utilize XOR encoding or RtlDecompressBuffer packing and are designed for DLL sideloading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the NeedyMantis first-stage loader (e.g., WinSparkle.dll variants) which employs anti-debug techniques such as NtQueryInformationProcess and ThreadHideFromDebugger, alongside stack-based string deobfuscation, to prepare for the extraction and execution of a secondary payload (e.g., encryptbase64.ps1).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of PowerShell commands using '[scriptblock]::Create' in conjunction with character array decoding or large negative integer-array patterns. This technique is commonly used to deobfuscate and execute obfuscated PowerShell scripts at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of PowerShell commands using '[scriptblock]::Create' in conjunction with character array decoding or large negative integer-array patterns. This technique is commonly used to deobfuscate and execute obfuscated PowerShell scripts at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of known Canon or Stardock software binaries (COTFileReadApp.exe, DeElevate64.exe) when spawned by msiexec.exe from non-standard locations such as Temp or AppData directories. This pattern is indicative of potential defense evasion, where adversaries leverage legitimate software to proxy execution or potentially perform side-loading activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Page 120 of 1870