Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
103
Detects the execution of PowerShell with suspicious command-line arguments (headless mode, hidden window, encoded commands) spawned by WScript.exe. This pattern is commonly associated with obfuscated script execution or fileless malware staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
205
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
001
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
001
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
001
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
001
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
001
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects the reflectively-loaded SectopRAT .NET payload by its combination of heavy calli (indirect call) opcode usage for control-flow flattening and its characteristic runtime string-decryption helper method used to resolve the C2 IP/port and other obfuscated strings
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
001
Detects the reflectively-loaded SectopRAT .NET payload by its combination of heavy calli (indirect call) opcode usage for control-flow flattening and its characteristic runtime string-decryption helper method used to resolve the C2 IP/port and other obfuscated strings
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
001
Detects the reflectively-loaded SectopRAT .NET payload by its combination of heavy calli (indirect call) opcode usage for control-flow flattening and its characteristic runtime string-decryption helper method used to resolve the C2 IP/port and other obfuscated strings
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
001
Detects the reflectively-loaded SectopRAT .NET payload by its combination of heavy calli (indirect call) opcode usage for control-flow flattening and its characteristic runtime string-decryption helper method used to resolve the C2 IP/port and other obfuscated strings
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
001
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
001
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
001
Page 142 of 1870