Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

FileFix JavaScript silently writes the malicious command to the clipboard the instant the lure button is clicked, producing a much shorter human-reaction interval between browser launch and shell spawn than a manually typed path would allow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
Detects the creation of registry keys associated with the installation of Chrome or Edge browser extensions, specifically targeting the behavior exhibited by the CrashFix malware which masquerades as an ad blocker to achieve persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
000
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
003
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
003
Detects HTTP and TLS activity associated with the DSCourier malware, specifically identifying attempts to retrieve configuration files disguised as common non-executable extensions (.jpg, .txt) or utilizing non-standard network ports like 8443, which are characteristic of this threat's command and control behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the use of 'winget configure' to retrieve and apply a Desired State Configuration (DSC) file from a remote HTTPS URL. This behavior can be abused to execute malicious configuration scripts directly from the internet.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the creation of a 'SystemIn.lnk' persistence shortcut on Windows systems using PowerShell and the WScript.Shell COM object. This activity is associated with the QUICAgent backdoor, part of the QUICSILVER operation, which uses temporary PowerShell scripts to establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects the execution of AutoIt3.exe or AutoIt-related scripts (.a3x, .au3) spawned by mshta.exe. MSHTA is a legitimate utility that can be abused to proxy the execution of malicious code, and in this context, it may be used to launch AutoIt scripts to evade security controls or execute payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects memory allocation (VirtualAlloc/AllocateVirtualMemory) or protection (VirtualProtect/ProtectVirtualMemory) API calls performed with 'EXECUTE_READWRITE' permissions where the call stack is missing, unbacked, or contains unknown modules. This behavior is highly indicative of code injection techniques where an adversary attempts to execute shellcode or reflectively load a payload into memory while attempting to hide the origin of the execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
This rule detects thread creation activities where the thread start address is spoofed to point to 'user32.dll!AnimateWindow'. This behavior is a technique used by the MinHook library (specifically in SparroWocky-style implementations) to conceal the true entry point of a thread and evade detection during process injection or thread hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
004
Detects reflective or beacon-style in-memory process injection where an injection-type action occurs in a target process, but no corresponding file creation event is recorded by the initiating process. This behavior is indicative of fileless malware loaders or reflective COFF-based execution, commonly used in adversary techniques like BOF (Beacon Object File) execution to bypass static disk-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
104
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
203
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
002
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
102
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
202
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
202
This rule detects potentially malicious activity originating from Microsoft Word (WINWORD.EXE). It monitors for two specific patterns: the creation of script files (.bat, .vbs, .cmd) with GUID-based filenames in non-temp directories, and the creation or execution of files matching known malicious hashes associated with the Hookedge malware family.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
5048
This rule detects potentially malicious activity involving LNK files being modified, created, or renamed in common locations (Desktop, Quick Launch, Start Menu) correlated with the creation of files ending in '.backup' within 30 minutes. It also independently detects the presence or execution of 'VLCAssistant.exe', which may indicate unauthorized launcher activity or masquerading.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
Detects VBScript droppers that utilize excessive 'WScript.Sleep' delays to bypass sandbox analysis, often combined with error suppression and downloader APIs to execute malicious payloads.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
16 days ago
003
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
102
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
002
Page 126 of 1870