Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects execution of potentially malicious scripts (a2.cmd) or unusual DLL loading behavior via rundll32.exe. This activity is often associated with staging or executing malicious payloads using non-standard naming conventions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where a Terraform provider process spawns a child process (go.exe or cmd.exe) to execute 'go run .'. This behavior is atypical for standard Terraform provider execution and may indicate the use of malicious providers that compile and execute code on-the-fly, a technique used to evade signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where a Terraform provider process spawns a child process (go.exe or cmd.exe) to execute 'go run .'. This behavior is atypical for standard Terraform provider execution and may indicate the use of malicious providers that compile and execute code on-the-fly, a technique used to evade signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where a Terraform provider process initiates a child process that is either the Go runtime (executing 'go run') or a Windows command shell (cmd.exe, powershell.exe). This behavior is often indicative of malicious code execution during the provider's execution lifecycle, potentially exploiting vulnerabilities in the Terraform provider ecosystem.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects a Go toolchain process (go.exe) spawning potentially suspicious child processes such as secondary 'go run' commands or Node.js execution. This behavior is indicative of a malicious Go module executing embedded or decrypted code during the build process, a tactic seen in supply chain attacks targeting development environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the execution of package management commands (npm, pip, python) within directories or command-line arguments containing 'veltrix' or 'veltrix-capital', which may indicate the use of malicious dependencies or cloned repository lures.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where a process that is not a recognized web browser accesses or enumerates the file storage path of the MetaMask browser extension. This behavior is indicative of unauthorized reconnaissance or credential theft attempt targeting cryptocurrency wallet data stored locally, often performed by malware following successful system compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects suspicious execution patterns characteristic of post-exploitation activity, such as invoking 'go run' or 'node' from non-standard directories like AppData or Temp, as well as the use of command-line routines to delete files after execution (often associated with self-deleting secondary payloads or persistence cleanup).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects network connections to the Slack API (api.slack.com) initiated by processes executing from temporary directories commonly used by the Go build system ('go-build'). This pattern is indicative of a second-stage RAT or malicious payload compiled on-the-fly using 'go run' or similar mechanisms, utilizing Slack's infrastructure for C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where Node.js, Python, or Go processes spawn command shell interpreters (cmd.exe, powershell.exe, etc.). This behavior is often indicative of C2 command execution by malware, such as the Graphalgo RAT, which may use these languages to execute shell-level commands after initial infection or payload execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where common scripting or development language runtimes (Go, Node.js, WScript, CScript) access sensitive configuration or credential files, such as AWS credentials, Kubernetes configs, SSH keys, or environment files. This activity is often indicative of credential harvesting or unauthorized access to sensitive secrets by potentially malicious scripts or processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
001
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
101
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
001
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
001
Matches known SHA-256 hashes of AvisLoader toolkit components recovered from an exposed staging server: the Windows loader client, UAC-bypass helper, and process-hiding DLL
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
001
Detects AvisLoader Windows loader requiring both decoy non-executable packer-named sections and an embedded c-toxcore developer build path to co-occur in a valid PE
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
001
Detects AvisLoader Windows loader requiring both decoy non-executable packer-named sections and an embedded c-toxcore developer build path to co-occur in a valid PE
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
001
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
001
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
001
Detects endpoint network connections to Heroku-hosted domains containing Google Ads tracking parameters (gclid, gad_source, gad_campaignid). This activity is associated with the initial staging phase of 'ShopEase' style malware delivery chains, where users are directed to decoy pages that prepare the environment for subsequent malicious browser-based actions.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
101
Page 144 of 1871