Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
002
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
Detects the creation of a file named 'DCRCVDrv.sys'. This filename is historically associated with malicious kernel-mode drivers used in cyberattacks, such as the DCRDRV exploit or related persistence/evasion mechanisms involving driver installation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects network connection events initiated by known beaconing-related process names. These processes are associated with command and control infrastructure or pivot nodes often used by adversaries for post-compromise activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects Node.js processes executing suspicious command lines that involve fetching and executing remote JavaScript code. This behavior is indicative of a loader or downloader script commonly used to pull and evaluate malicious payloads at runtime, specifically referencing indicators associated with 'GHAPPIER'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
14 days ago
101
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
101
Detects the installation and execution of Cloudflare Tunnel (cloudflared.exe) as a Windows service. Adversaries may abuse this utility to create unauthorized persistent network tunnels, enabling covert remote access to the internal network. This rule correlates process creation events involving 'service install' or 'tunnel run' commands with Windows service installation events referencing the cloudflared binary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
001
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
104
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
104
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
009
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
16 days ago
102
Detects the execution of Node.js or Python interpreters from user-writable directories (AppData/Local) that are executing specific script files. This pattern is indicative of potential malicious activity where legitimate scripting languages are leveraged to run unauthorized payloads dropped into the user profile.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
002
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
102
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
002
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
102
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
202
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
002
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
002
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
2014
Page 148 of 1871