Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects modifications to Group Policy Objects (GPOs) performed by accounts identified as domain administrator-equivalent (based on naming conventions) within 60 minutes of a successful logon from a device, potentially indicating GPO weaponization by an adversary using a compromised account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
104
This rule detects PowerShell script blocks containing a suspicious combination of Base64-like character sets and Cyrillic characters. This technique is often used in obfuscated payloads to evade static analysis signatures or to hinder human readability by inserting non-Latin characters within encoded content, which may trigger different parsing behaviors in various environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects unauthorized attempts to disable or modify Windows Firewall settings across multiple devices. The rule identifies suspicious registry modifications, firewall service termination events, or security policy changes that suggest an adversary is attempting to impair defensive mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the use of legitimate Windows binaries (Rundll32, Wscript, Cscript, and Regsvr32) to execute scripts, HTML applications, or remote scriptlets. This pattern is commonly associated with adversary techniques to proxy execution of malicious code, bypass application controls, or retrieve payloads from remote servers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the execution of Windows Terminal, PowerShell, or pwsh processes spawned directly by explorer.exe that do not originate from standard Start Menu search or navigation host processes. This pattern is indicative of the user triggering the 'Power User' (Win+X) menu, often associated with adversary attempts to leverage ClickFix-style social engineering lures that rely on the user interacting with specific UI elements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
FileFix lures append a real-looking file path after a '#' comment character so the Explorer address bar visually shows a benign path while the PowerShell prefix executes silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Some FileFix/ClickFix chains pivot execution through the mshta.exe living-off-the-land binary immediately after the Explorer address-bar entry, before dropping the final payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
FileFix's core mechanism abuses the HTML input type=file element; clicking a lure button launches explorer.exe from the browser while JavaScript copies a disguised PowerShell command to the clipboard.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
FileFix loader chains abuse trusted code-hosting platforms like Bitbucket/GitHub to host staged payload components, exploiting domain trust to evade network detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
FileFix lures append a real-looking file path after a '#' comment character so the Explorer address bar visually shows a benign path while the PowerShell prefix executes silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Some FileFix/ClickFix chains pivot execution through the mshta.exe living-off-the-land binary immediately after the Explorer address-bar entry, before dropping the final payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
FileFix's core mechanism abuses the HTML input type=file element; clicking a lure button launches explorer.exe from the browser while JavaScript copies a disguised PowerShell command to the clipboard.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
StealC v2, the payload consistently delivered via FileFix campaigns, is capable of stealing cryptocurrency wallet data alongside credentials and VPN configs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Acronis TRU (Sept 2025) documented a FileFix campaign where a PowerShell loader downloads images from Bitbucket that conceal embedded malicious components, ultimately deploying a Go-based loader and StealC.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
The FileFix StealC campaign's final-stage loader is written in Go and performs VM/sandbox checks plus string encryption before executing the infostealer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Because FileFix commands are typed/pasted directly into the Explorer address bar rather than downloaded, executed content never receives a Mark-of-the-Web tag, sidestepping SmartScreen-style controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
A FileFix sibling technique dubbed DownloadFix uses a broken/incomplete download to prompt the victim to manually execute a .cmd file via the browser's Downloads shortcut instead of the Explorer address bar.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
105
After the initial FileFix paste-and-execute step, observed campaigns chain into a secondary download of the real payload using LOLBins or PowerShell web clients.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Acronis reported a multilingual FileFix phishing site using anti-analysis techniques and advanced obfuscation, chaining into a Go-based loader with string encryption before deploying StealC.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
This rule detects a behavioral chain characteristic of the KongTuke/LandUpdate808 threat actor group. It identifies the correlation between a browser initiating a network connection to a domain with a low-reputation top-level domain (TLD) and that same browser process launching 'explorer.exe' within a 60-second window. This behavior is associated with social engineering lures (fake CAPTCHA) that encourage users to execute clipboard commands, which trigger file-picker dialogs via explorer.exe to facilitate follow-on malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Page 125 of 1870