Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the execution of a malicious Electron-based installer masquerading as Anthropic's Claude AI (ClaudeOpus5-desktop.exe). The rule monitors for the specific filename or known malicious hashes, as well as the spawning of an embedded malicious loader process associated with the RevStealer infection chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
002
Detects a suspicious behavior chain characteristic of information stealers like Vidar. The process first modifies the Windows Registry to disable the Windows Error Reporting (WER) UI (an anti-analysis technique to suppress crash dialogs) and shortly thereafter initiates an outbound network connection to a public IP, likely for C2 communication or data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
This rule detects potential execution of Vidar Stealer by identifying specific diagnostic loader strings (e.g., 'Loader: write failed') within file modification and process execution events. The presence of these strings in file metadata or command-line arguments indicates stage-specific activity related to the malware's loading process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
104
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
104
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
204
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
004
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
104
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
17 days ago
103
Detects instances where wscript.exe spawns cscript.exe with a VBScript file in the command line. This sequence often indicates an attempt to run obfuscated or malicious scripts using built-in Windows scripting engines, which is a common technique for initial access or execution by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
This rule detects access (creation, modification, renaming, or reading) to browser-specific sensitive credential files ('Login Data' or 'Local State') located in the user data directories of Chrome, Edge, or Brave. It filters out legitimate activity by ensuring the initiating process is not the browser's own application executable, which is indicative of credential theft or dumping by unauthorized tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects the execution of Windows Package Manager and configuration-related server binaries (WindowsPackageManagerServer.exe, ConfigurationRemotingServer.exe, DSCourier.exe) when not initiated by the authorized 'winget.exe' process. The rule further correlates these processes with the absence or delayed loading of the 'Microsoft.Management.Configuration' library, which may indicate unauthorized usage or tampering with package/configuration management components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
This rule monitors for the creation or renaming of executable files (.exe) within the 'Users\Public' directory. This directory is commonly used by adversaries for staging malicious payloads, as it is writable by standard users and often overlooked by security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects the execution of PowerShell or Command Prompt with common adversarial flags (e.g., encoded commands, bypass, hidden windows) initiated by the Windows Explorer process. This pattern correlates the execution event with recent user interaction with the Windows Run MRU registry key, suggesting a possible manual execution of malicious commands via the 'Run' dialog box.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects usage of msiexec.exe to execute an MSI package from a remote URL. This technique is often used to download and execute malicious installers directly from the internet, bypassing local file storage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects the execution of PowerShell with obfuscation-related flags (-NoProfile, -WindowStyle Hidden, -EncodedCommand) initiated by common scripting interpreters (wscript.exe, mshta.exe, cscript.exe). This pattern is often indicative of malicious scripts, such as HTA or VBScript files, attempting to execute encoded PowerShell commands in a high-privilege context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, no profile, encoded command) initiated by wscript.exe or mshta.exe. This pattern is commonly used by adversaries to execute obfuscated malicious payloads while proxying the execution through legitimate Windows utilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
This rule detects potential command-and-control (C2) activity by monitoring network connections to a specific malicious IP address (91.196.32.232) over port 8089 and correlating this with suspicious PowerShell commands. The rule looks for PowerShell scripts executing 'Invoke-RestMethod' to reach out to the C2, as well as obfuscated or beaconing-like behavior involving 'Start-Sleep' intervals paired with C2-related keywords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the creation or modification of a Windows Registry 'Run' key that triggers a PowerShell script named 'Update.ps1' with hidden execution policies. The rule also captures direct execution of the same PowerShell script via process creation events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Page 136 of 1870