Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects instances where browser processes (Chrome or Edge) are spawned by smartscreen.exe and subsequently access sensitive browser storage files such as Login Data, Cookies, or Local State. This pattern is indicative of a process injection or masquerading chain used to extract credentials or session data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
202
Detects potential lateral movement or pivot attempts by correlating repeated failed RDP logons (RemoteInteractive) against sensitive targets (Domain Controllers, File Servers, Backup Servers) with concurrent security tool blocks (e.g., Microsoft Defender Antivirus, Exploit Guard) on the originating beachhead device within a 4-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
302
Detects the execution of PowerShell with command-line arguments that suggest programmatically capturing or redirecting console output using ScriptBlock techniques (Create, Console, In, ReadToEnd). This pattern is often associated with obfuscated script execution, in-memory payloads, or attempts to bypass logging by capturing output via .NET streams.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
102
Detects instances where Python interpreters (python.exe or pythonw.exe) are executed from a subdirectory within ProgramData that matches a 32-hex character pattern, initiated by the 7zip archive utility (7za.exe). This pattern is indicative of a self-extracting archive or malicious installer unpacking and executing Python scripts in a stealthy, non-standard location.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
This rule detects a malicious execution chain starting with an MSI file being launched by explorer.exe from user-downloaded folders. The installer spawns chrome.exe, drops a specific loader file (e.g., PavokwiLoader.exe or Loader.exe) into the %LOCALAPPDATA%\Temp\modules\ directory, and establishes persistence via the HKCU 'Load' registry value pointing to that location.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
102
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
102
This rule detects potentially malicious process execution chains where VBScript or unknown/suspicious binaries (such as ProfileQuickHost.exe) are used to launch Node.js processes, specifically targeting JavaScript files or VBScript agents. This pattern is often associated with the execution of remote access trojans (RATs) or custom malware loaders.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
005
Detects the execution of PowerShell via WScript or CScript scripts that contain command line arguments indicative of a file download cradle (e.g., Invoke-WebRequest, IWR, Net.WebClient, DownloadFile, DownloadString, or BITS transfer). This pattern is frequently used by adversaries to download and execute second-stage payloads or RMM agents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects the execution of PowerShell with the -NoProfile flag initiated by wscript.exe or cscript.exe, containing sleep/delay commands alongside network download functions. This pattern is characteristic of malware loaders or RMM phishing kits attempting to evade sandbox analysis before initiating a remote download.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects unauthorized processes, excluding standard web browsers, accessing sensitive browser files such as Login Data, Cookies, Web Data, and Local State. This activity is indicative of credential harvesting malware attempting to steal authentication cookies, saved passwords, or browser profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects a malicious payload masquerading as a ClaudeDesktop installer that uses DLL sideloading via a tampered libcef.dll and a repurposed JetBrains binary to execute the SectopRAT .NET RAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects OnyxC2 RunPE injection behavior where a process drops or loads a suspicious sideloaded DLL (specifically borlndmm.dll) and immediately initiates a secondary process instance, indicative of process hollowing or memory unpacking of a malicious payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
103
Detects the creation or presence of Windows Shortcut (LNK) files that use deceptive double extensions (e.g., .pdf.lnk) and specific filenames related to South Korean financial reporting, a technique associated with the threat actor Kimsuky to entice users into executing malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the use of WinRAR to open or extract password-protected ZIP archives containing 'Setup_File' in the filename, immediately followed by the execution of a file extracted into a WinRAR temporary directory. This behavior is associated with the OnyxC2 delivery chain, where attackers use password-protected archives to bypass security scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects instances where a process spawns a child process using the exact same executable image path, specifically when the executable is located in user-writable directories such as Downloads or AppData\Local\Temp. This behavior is a common indicator of process hollowing or self-injection techniques used by malware, such as loaders that decrypt payloads in memory and then spawn a new, hollowed instance of themselves to execute the malicious code, frequently observed during post-exploitation activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects the use of PowerShell processes that employ command-line encoding (e.g., -enc, -EncodedCommand) in conjunction with download-related cmdlets (e.g., DownloadString, IEX, Invoke-WebRequest), or instances of PowerShell spawned as a child process of another PowerShell process. This pattern is indicative of a loader or stage-one script fetching additional malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects the MSBuild.exe process adding new root or intermediate certificate authorities to the Windows certificate stores. This activity is indicative of potential malicious PKI infrastructure staging, which can be used to facilitate adversary-in-the-middle (AiTM) attacks or bypass certificate validation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
103
Detects the execution of PowerShell scripts containing a combination of Base64 encoding, compression (Deflate/Gzip), and UTF-32 decoding. This specific layering is commonly used to obfuscate malicious payloads and evade signature-based detection mechanisms in PowerShell environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects multiple endpoints setting their desktop wallpaper to a common file located on a remote UNC path or containing 'sysvol'. This behavior is often indicative of GPO-based configuration for persistence or malware staging, where a malicious 'payload.jpg' is used as a cover or to deliver code via vulnerabilities in image parsing libraries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects modifications to the Windows legal notice registry keys (legalnoticecaption, legalnoticetext) under the System policies registry hive. These keys are used to display a message to users during the login process, and are frequently abused by adversaries for persistence messaging, defacement, or to deliver payloads via social engineering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
This rule detects the execution of LNK or HTA files from a WebDAV share (DavWWWRoot) using common Windows binaries like mshta.exe, wscript.exe, cscript.exe, or explorer.exe. This pattern is commonly associated with the 'ClickFix' technique, where users are lured into opening malicious files hosted on remote WebDAV shares to achieve code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Page 124 of 1870