Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects rapid deletion of Windows Defender or WdFilter service registry keys by non-standard processes (not System or ntoskrnl.exe). This pattern is consistent with kernel-mode tamper protection bypass attempts, such as the use of the BTR.sys driver to force the removal of defensive configuration entries, effectively disabling Windows Defender.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
103
Detects potential abuse of SeLoadDriverPrivilege to load unsigned or malicious drivers, often associated with Bring Your Own Vulnerable Driver (BYOVD) attacks. The rule identifies the creation of randomized service keys used to facilitate driver loading, followed by the actual loading of a driver, or explicit command-line references to the privilege being utilized.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the presence or execution of the 'Boot Time Removal Tool' (BTR.sys) driver when it originates from locations outside of the legitimate Windows Defender platform or is initiated by processes not associated with the Defender ecosystem. This behavior is indicative of potential BYOVD (Bring Your Own Vulnerable Driver) attacks where attackers deploy known vulnerable drivers to gain kernel-mode privileges or interfere with security software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects PowerShell command lines that perform suspicious string manipulation using the .Replace() method on specific obfuscated characters, followed by a Base64 decoding operation. This pattern is commonly used by attackers to reassemble and decode fragmented or obfuscated payloads on the fly to evade static analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
203
Detects execution of JavaScript files using the Windows Script Host (wscript.exe or cscript.exe). This is a common technique used by attackers to execute malicious scripts, often delivered via phishing or as secondary payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the execution of MSBuild.exe when spawned by a PowerShell process. This is a common pattern for proxying execution of malicious code, such as the LxBaseRAT, by leveraging MSBuild's inline task capability to execute C# or VB.NET code within a signed Microsoft binary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the abuse of WerFaultSecure.exe or similar Windows Error Reporting processes, invoked with debugging or dumping flags against security/EDR process names, or spawned by unexpected parent processes. This technique is often used to freeze security tools (EDR-Freeze) by exploiting process suspension via mini-dump handles.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects activity associated with the SharePoint ToolShell exploitation chain, specifically monitoring the w3wp.exe process for spawning suspicious child processes like cmd.exe or powershell.exe, and the creation of unexpected .aspx files within the SharePoint LAYOUTS directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects instances where the Node.js runtime environment (node.exe) deletes a file named 'sharedLoad.min.js' located within a 'node_modules' directory. This behavior is indicative of anti-forensic cleanup activities where malicious npm packages attempt to remove their own footprints or temporary artifacts post-execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects Xray-core C2 tunnel traffic where the TLS SNI is spoofed to appear as 'dl.google.com'. The detection specifically looks for this behavior originating from non-browser processes such as 'wkspbroker.exe' or 'radcui.dll', which is indicative of malicious tunneling activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the modification of registry keys under HKCU\Software\Classes\CLSID\...\InProcServer32, which is a common method for achieving persistence. The rule flags when these registry keys point to file paths within the local user profile (AppData), which is frequently used by malicious actors to load custom DLLs when the corresponding COM object is initialized.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
17 days ago
103
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
17 days ago
403
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
17 days ago
103
Detects the execution of known remote access tools (AnyDesk, TeamViewer, Quick Assist) on Windows systems. The rule is intended to be used in a correlated detection pipeline that identifies a multi-stage attack chain involving an initial email-bombing flood followed by an external Microsoft Teams vishing call impersonating IT support.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the execution and behavioral patterns associated with the malicious 'indexed-btree' npm package. The rule specifically looks for code patterns where a malicious loader is injected into 'BTree.prototype.set' and triggered at runtime. It also monitors for suspicious process spawning behavior, such as running node processes with detached and hidden windows flags, often used by the package to maintain persistence or execute malicious payloads silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects instances where the AnyDesk process spawns cmd.exe or executes a batch script, which is a common indicator of an attacker performing post-exploitation activities via a remote access session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
704
Detects the creation of a shortcut file named 'AppUpdateHelper.lnk' within the Windows Startup folder by the 'UpdateAssistant.exe' process. This pattern may indicate an attempt to establish persistence by an application posing as an update process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
103
Detects the execution of the Windows Workspaces Broker process (wkspbroker.exe) when it loads a library (DLL) from a path within the RemoteApp Gateway directory under LOCALAPPDATA. This behavior is associated with DLL side-loading techniques used to execute malicious payloads such as the Xray-core implant.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
This rule detects the execution of common Node.js package managers (npm, yarn, pnpm) attempting to install specific dependencies that match known patterns of malicious or typosquatted packages often used in supply chain attacks. The detection focuses on suspicious package names that mimic common data structure library naming conventions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
204
Detects instances where a Node.js process spawns another Node.js process to execute a JavaScript file located within the node_modules directory. This pattern is commonly observed when malware or malicious scripts attempt to execute payloads from within project dependencies, potentially hiding malicious activity within seemingly legitimate library paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
304
Page 150 of 1871