Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
106
Detects instances where AI-assisted development tools (such as Claude, Codex, Copilot, or Gemini) initiate command-line processes (e.g., shells, interpreters, or network utilities) with arguments indicative of credential access, reconnaissance, or sensitive file interactions.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
709
Detects an exploitation chain originating from a Chrome browser process, characterized by the execution of an anomalous child process followed by the creation of an executable file named 'chrome_cleanup.exe' within a short time window. This sequence is indicative of multi-stage exploitation, involving remote code execution via browser vulnerability and subsequent privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
203
Detects the use of PowerShell's Start-Sleep cmdlet with a duration of 3 minutes or longer within process command lines. This technique is commonly used by malware, such as ClickFix-style droppers, to bypass sandbox time-based analysis by delaying execution until the sandbox timeout period has elapsed.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
19 days ago
205
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
001
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
004
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
304
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
001
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
101
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
101
This rule detects suspicious PowerShell execution initiated by a Node.js process (node.exe). It monitors for command lines containing common bypass flags (-NoProfile, -NonInteractive, -ExecutionPolicy Bypass) and a specific string pattern 'wra-ps-', which is often associated with malicious scripts or remote access trojans (RATs) being executed via a Node.js application.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
004
This rule detects suspicious activity where a node.exe process, often associated with a node-pty terminal emulation, launches common Windows command-line shells (cmd.exe, powershell.exe) from specific file paths or directories. This behavior is indicative of a Node.js-based Remote Access Trojan (RAT) or shell spawning mechanism being used to establish command and control or persistence on a Windows host.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
104
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
004
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
204
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
003
Detects known file hashes associated with SideCopy/ReverseRAT.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
003
Detects known file hashes associated with SideCopy/ReverseRAT.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
003
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
103
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
203
Detects the creation of a Windows scheduled task via schtasks.exe where the initiating process is located in common user-writable temporary or non-standard directories (e.g., AppData, Temp, or Public folders). This behavior is often indicative of malicious persistence mechanisms being established by a dropper or stage-one malware payload.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
000
Detects a behavioral chain where a process establishes persistence using a 'WindowsUpdate' Registry Run key or a scheduled task, followed within five minutes by an outbound network connection from the same process. The rule specifically excludes cases where a ZIP file was written to disk, identifying potential in-memory staging for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
000
Page 140 of 1870