Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects instances where msiexec.exe is used in conjunction with specific application names (Spotify, Zoom, Teams) in the command line, and subsequently launches suspicious child processes such as wscript.exe, cscript.exe, or powershell.exe with specific script or executable arguments. This pattern is often associated with malicious installers or trojanized software attempting to execute embedded payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
103
Detects endpoint behavior consistent with AI-assisted exploit development, characterized by the execution of reverse engineering and vulnerability research tools (e.g., IDA Pro, Ghidra, AFL) interleaved with frequent outbound network connections to LLM APIs, followed by the local compilation of a new executable or DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects anomalous, high-volume file access by a single process, followed by local file compression or archiving, and subsequent outbound data transfer to a non-internal IP address. This pattern is characteristic of automated agents (like those used in the GTG-1002/Anthropic AI-orchestrated campaigns) performing rapid data triage and staging for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects Node.js processes exhibiting network activity patterns consistent with 'EtherHiding' style C2 infrastructure, characterized by multiple distinct connections to external WebSocket hosts on non-standard TCP ports within a short timeframe, potentially following interaction with a blockchain/JSON-RPC endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects anomalous activity from IDEs or AI coding assistant extension host processes (e.g., VS Code, Cursor, JetBrains). The rule alerts when these processes spawn children that access sensitive local credential files, perform network connections to non-standard/unexpected domains, or modify critical CI/CD build script configuration files, which is indicative of a supply chain compromise within the developer environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects the removal of persistence mechanisms related to the 'ComponentTask33Agent' task, specifically the deletion of a scheduled task or registry Run key, followed by the deletion of associated files within specific Microsoft-themed AppData subdirectories within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects anomalous child process spawning from common web browsers or productivity applications (e.g., Office, Acrobat) on hosts that have recently communicated with known LLM or code-generation APIs. This behavioral correlation is intended to identify the potential execution of AI-generated exploit code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects the persistence sequence associated with 'ChainScript', which involves creating a hidden scheduled task using PowerShell or specific scripts, and a fallback mechanism that creates a registry run key entry if the task creation fails. The rule monitors for PowerShell commands, bridge script execution, and registry modifications involving the 'ComponentTask33Agent' or wscript.exe executing an '_agent.vbs' file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects potential runtime polymorphic malware that modifies its own executable or script content while simultaneously communicating with generative AI or LLM API endpoints. This behavior indicates an adversary using LLMs to regenerate obfuscated code or mutate malware signatures dynamically at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects the creation of specific forensic log files (browser_decryption.log, sends.log) within the %TEMP% directory. These files are indicators of the data collection stage performed by the Rapuncel infostealer prior to archiving and exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects ZIP archives exceeding 100MB that contain specific DLL filenames often used for junk-padding to evade sandbox analysis. This technique is observed in brand-impersonation campaigns targeting users with fake security or authentication software lures.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the staging of ChainScript files into specific, masquerading subdirectories within user AppData folders that mimic legitimate Windows system paths. This activity is indicative of the _scatter.ps1 script redistributing components such as the Node.js runtime, agent configuration, and helper utilities before execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects instances where common script interpreters (powershell.exe, cmd.exe, mshta.exe, etc.) are launched by developer-centric processes (node.exe, npm.exe, Code.exe) with suspicious command-line arguments often used for reconnaissance, payload downloading, or obfuscated command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the execution of known remote access or remote monitoring software (such as TeamViewer, AnyDesk, or ScreenConnect) on corporate-issued Windows endpoints. The rule triggers on process execution patterns associated with unauthorized remote control, specifically looking for indicators of unattended access or silent installation commonly used by overseas actors to remotely operate company-issued laptops assigned to fraudulently hired identities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects instances where Microsoft Visual Studio Code (Code.exe) spawns common interpreters or command-line tools (such as node, python, cmd, or powershell) that are not associated with known internal VS Code process behaviors like renderer tasks or tunnel operations. This activity may indicate malicious use of the integrated terminal or extension execution contexts to execute unauthorized code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the execution of known remote access or remote monitoring software (such as TeamViewer, AnyDesk, or ScreenConnect) on corporate-issued Windows endpoints. The rule triggers on process execution patterns associated with unauthorized remote control, specifically looking for indicators of unattended access or silent installation commonly used by overseas actors to remotely operate company-issued laptops assigned to fraudulently hired identities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects Node.js or Python processes exhibiting behavior characteristic of information-stealing malware (such as the WaterPlum suite: BeaverTail, InvisibleFerret, OtterCookie, StoatWaffle). The rule monitors for these processes accessing sensitive files related to browser credentials, cryptocurrency wallets, scanned identification documents, or performing collection activities like keylogging and screen capturing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the use of PowerShell cmdlets (Add-MpPreference or Set-MpPreference) to modify Microsoft Defender exclusions (paths, processes, or extensions). This behavior is often associated with adversaries attempting to evade security detection by excluding malicious files or processes from being scanned by Microsoft Defender.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
203
Detects suspicious command-line patterns typically used for downloading or executing malicious payloads, such as curl, base64 encoding, and PowerShell web requests, when spawned directly from Node.js or Visual Studio Code processes. This behavior is associated with supply chain compromises and loader activity (e.g., WaterPlum/Contagious Interview) targeting development environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Page 145 of 1871