Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the presence or execution of artifacts associated with the TrustSink proof-of-concept (deploy.py, cleanup_eam.py, deploy_state.json), which is used to register or remove rogue Entra authentication providers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects anomalous process spawning behavior initiated by Python interpreters (pip/conda) on machine learning developer or training hosts, which may indicate a supply chain compromise where a malicious package executes code during or shortly after installation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
This rule detects three distinct suspicious behaviors related to potential file manipulation and persistence mechanisms: 1. Use of 'copy /b' command to reconstruct files from fragments (e.g., header.doc, body.doc), commonly associated with file joining or data reconstruction. 2. File access within '_rels' directories targeting document fragments, often used in malicious document analysis or extraction. 3. Execution of 'Windowsupdate.exe' from the 'AppData\Local' directory, a technique often used for masquerading as a legitimate Windows service to establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the execution of the Windows FTP client (ftp.exe) using command-line arguments that include scripts (-s:), initiated by unconventional parent processes such as explorer.exe or cmd.exe. This behavior is often associated with the execution of automated FTP scripts for data exfiltration or malware delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
This rule detects potential AI/ML supply chain compromise by monitoring for package installations (via pip, conda, poetry, etc.) from non-standard repositories, direct URLs, or version control systems within data science and CI/CD pipelines (e.g., Jupyter, Airflow, Jenkins). It further correlates this activity with subsequent suspicious outbound network connections from the host, which is indicative of slopsquatting or malicious dependency execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects suspicious processes frequently polling Hugging Face repository endpoints (discussions, raw files, commits). This behavior is characteristic of adversaries using public code/dataset hosting services as a covert command-and-control (C2) channel to fetch instructions or exfiltrate data, bypassing traditional network filters by blending in with legitimate developer traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
103
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
003
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
003
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
103
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
003
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
003
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
003
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
003
This rule detects the loading of a driver named 'eb.sys' (or matching a specific SHA256 hash) paired with the creation of a Windows service for that driver via the 'sc' command. This behavior is indicative of potential rootkit installation or driver-based persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects instances of node.exe being spawned by potentially suspicious parent processes like msiexec.exe, wscript.exe, cscript.exe, or explorer.exe, or being executed from unusual locations often associated with malicious staging or masquerading, such as Windows Libraries or Themes directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
This rule detects Terraform CLI execution of the 'init' command correlated with network access to HashiCorp AWS registry domains, or the presence of Terraform lock files in specific sensitive or project-related directory paths. This combination often indicates infrastructure-as-code management activities or potential misuse of Terraform in a production environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects execution of Windows Installer packages (MSI) masquerading as common software installers (Spotify, Zoom, Microsoft Teams) using known ChainScript-style naming patterns and suspicious command-line parameters (e.g., ALLUSERS=2, MSIINSTALLPERUSER=1) or invocation from common user-mode applications like cmd.exe, powershell.exe, or explorer.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the execution of regsvcs.exe when initiated by PowerShell, or when invoked with specific command line arguments indicating .NET reflection (GetType, GetMethod, method.Invoke) typically associated with fileless execution or proxying malicious code. The rule specifically targets instances involving .NET Framework directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects unauthorized access to web browser credential stores (e.g., Login Data, Cookies) by non-browser processes, such as scripting engines (PowerShell, WScript) or common LOLBins (MSBuild, InstallUtil). This behavior is indicative of credential theft or data exfiltration attempts by malicious software, including stealers like PureLog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects access to sensitive cryptocurrency wallet files (e.g., wallet.dat, keystore) by processes typically associated with LOLBins (Living-off-the-land Binaries) like PowerShell, MSBuild, or non-executable utilities. This activity is indicative of credential theft or data staging for exfiltration of cryptocurrency assets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Page 137 of 1870