Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the ChainScript RAT, executing via a masqueraded Node.js process, enumerating Local Extension Settings for browser wallet plugins. This reconnaissance activity is a precursor to exfiltrating crypto wallet data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the spawning of script interpreters or loaders by Visual Studio Code (Code.exe) shortly after a workspace is initialized, specifically looking for command-line arguments referencing .vscode or tasks.json. This behavior is consistent with exploitation techniques where a user accepts a 'Trust Workspace' prompt, allowing malicious tasks defined in a repository's .vscode folder to execute.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects specific malicious archive payloads associated with NeedyMantis that contain a second-stage loader and spoofed system DLLs (e.g., dnsapi.dll, ws2_32.dll, msvcrt140.dll). These archives utilize XOR encoding or RtlDecompressBuffer packing and are designed for DLL sideloading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the NeedyMantis first-stage loader (e.g., WinSparkle.dll variants) which employs anti-debug techniques such as NtQueryInformationProcess and ThreadHideFromDebugger, alongside stack-based string deobfuscation, to prepare for the extraction and execution of a secondary payload (e.g., encryptbase64.ps1).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of PowerShell commands using '[scriptblock]::Create' in conjunction with character array decoding or large negative integer-array patterns. This technique is commonly used to deobfuscate and execute obfuscated PowerShell scripts at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of PowerShell commands using '[scriptblock]::Create' in conjunction with character array decoding or large negative integer-array patterns. This technique is commonly used to deobfuscate and execute obfuscated PowerShell scripts at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of known Canon or Stardock software binaries (COTFileReadApp.exe, DeElevate64.exe) when spawned by msiexec.exe from non-standard locations such as Temp or AppData directories. This pattern is indicative of potential defense evasion, where adversaries leverage legitimate software to proxy execution or potentially perform side-loading activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the creation of Windows Registry Run keys with names mimicking known applications (e.g., 'Canon Configuration Reader' or 'Stardock DeElevation Tool'). These naming patterns are highly suspicious and indicative of attempts to achieve persistence or perform defense evasion via registry-based autostart execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects execution of msiexec.exe via the Windows Run dialog (launched by explorer.exe) that utilizes a remote URL for an MSI installer alongside suspicious property flags ('ORG_NOTE', 'passive'). This pattern is associated with 'ClickFix' social engineering campaigns where users are instructed to copy-paste commands to 'fix' a display issue, leading to the execution of malicious installers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects instances where identified RAT-associated or potentially malicious parent processes spawn command-line interpreters (e.g., cmd, powershell) or execute archive management commands, which is indicative of secondary stage payload deployment or automated execution following initial compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects network connection attempts to known public DNS-over-HTTPS (DoH) resolvers from specific binaries identified as host processes for SectopRAT, a malware often associated with ClickFix social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the creation of files associated with Psychedelic Stealer's persistence mechanism. The malware establishes persistence by installing a malicious native messaging host configuration file (com.lunex.explorer.json) and associated malicious scripts (host.ps1 or host.bat), which allows it to intercept and manipulate web browser native messaging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the creation of files associated with Psychedelic Stealer's persistence mechanism. The malware establishes persistence by installing a malicious native messaging host configuration file (com.lunex.explorer.json) and associated malicious scripts (host.ps1 or host.bat), which allows it to intercept and manipulate web browser native messaging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the use of PowerShell with a hidden window ('-w hidden') to execute the 'Add-MpPreference' cmdlet to configure Windows Defender exclusions. This combination is often indicative of malicious activity, such as attempting to bypass security controls stealthily following a UAC bypass or initial access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
This rule detects the creation of a scheduled task named 'psychedelicloveUtils' on Windows systems. This specific task name is associated with the persistence mechanism of the Psychedelic Stealer malware. The detection leverages command-line monitoring for the task creation request and identifies related file-system modifications in the Windows task registry structure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects suspicious execution patterns involving msiexec where a PowerShell process launches or is the parent of an MSI installation occurring from the %TEMP% directory with a GUID-based filename, or when msiexec executes an application from within %AppData%\Local\Programs. This pattern is often associated with fileless malware, ClickFix-style social engineering attacks, or suspicious persistence/installation behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects instances where an unexpected process loads both 'amsi.dll' and .NET runtime modules ('clr.dll' or 'mscoree.dll'). This behavior is frequently associated with malicious, position-independent shellcode that attempts to disable AMSI scanning and host the CLR in-memory to execute malicious .NET assemblies or payloads, avoiding standard .NET execution environments like PowerShell or msbuild.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of known remote-access or screen-sharing software (e.g., TeamViewer, AnyDesk, RDP) within 30 minutes of launching common video conferencing applications (e.g., Zoom, Teams, Google Meet). This pattern is consistent with an adversary remotely assisting an unauthorized user during a live coding interview or similar assessment process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
204
Detects a specific behavioral chain associated with the CHOSEN BRICK implant. This rule identifies when a suspected malicious process writes image/screenshot files (.png, .jpg, .bmp) to disk, followed by a network connection to the Telegram Bot API within a 15-minute window, suggesting potential data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
This rule detects the creation, modification, or renaming of files within specific sensitive directories under Local AppData (such as ComponentTask33, INetCache/FilterManager, or Shell/RemoteTempPrimary) that are closely timed with the execution of a PowerShell script named '*_scatter.ps1'. This behavior is indicative of potential malicious staging, data dropping, or modular deployment associated with a specific script-based attack chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
005
This rule detects suspicious process lineage where Python (python.exe or pip.exe) is initiating the execution of Windows command shell (cmd.exe) or Windows calculator (calc.exe). This pattern is often associated with exploitation of malicious Python site-hook files or similar techniques where a Python environment is leveraged to spawn secondary processes, potentially leading to unauthorized command execution.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
10 days ago
000
Page 121 of 1870