Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects instances where the IIS worker process (w3wp.exe) writes a new .aspx file into the 'MemberFiles' directory. This behavior is highly characteristic of webshell deployment following a successful file upload exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
Detects web server requests for .aspx files where the User-Agent string identifies as Windows PowerShell and includes the zh-CN locale setting. This behavior is often characteristic of automated exploitation tools or web shells (like China Chopper) interacting with compromised web servers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
Detects a multi-stage activity where PowerShell is used to download a ZIP file, followed by the execution of a batch script (1.bat) that subsequently launches LockScreenContentServer.exe. This behavior is indicative of a DLL side-loading chain designed to execute malicious code via legitimate processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
Detects a multi-stage activity where PowerShell is used to download a ZIP file, followed by the execution of a batch script (1.bat) that subsequently launches LockScreenContentServer.exe. This behavior is indicative of a DLL side-loading chain designed to execute malicious code via legitimate processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
This rule detects instances where a process matching a known sideload-vulnerable binary (such as werfaultsecure or wuauclt) spawns a PowerShell process that executes commands commonly used for Active Directory reconnaissance and system information discovery. This behavior is indicative of post-compromise activity, specifically reconnaissance phases performed by malware loaders like Lorem Ipsum.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
Detects instances where the IIS worker process (w3wp.exe) spawns the Windows command shell (cmd.exe) to execute common reconnaissance commands such as whoami, hostname, systeminfo, and net user. This behavior is strongly indicative of post-exploitation activity following a successful web shell deployment on a web server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
003
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
406
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
003
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
003
Detects outbound network connections to common TOR entry, guard, or client service ports, or the execution of TOR-related processes. This behavior may indicate an adversary establishing C2 communication channels or attempting to perform anonymized data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
003
Detects instances where a process contacts multiple distinct AI-provider domains within a short time frame while simultaneously performing suspicious operations, such as accessing the LSASS memory, executing process injection, or establishing WMI persistence. This pattern is indicative of a potential 'ClosedQuorum' adversary behavior involving data exfiltration or AI-assisted malicious activity.
chris tano@christano
avatar
Detections.ai Community
11 days ago
007
Detects anomalous process execution by PeopleSoft application server processes (e.g., psappsrv, jsvc) immediately following an inbound network request. This behavior is indicative of exploitation of a Java deserialization gadget chain, such as those used by the threat actor UNC6240 to achieve Remote Code Execution (RCE) and spawn command interpreters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
003
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
103
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
003
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
101
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
101
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
001
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
Page 15 of 1866