Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where a Node.js process spawns another Node.js process to execute a JavaScript file located within the node_modules directory. This pattern is commonly observed when malware or malicious scripts attempt to execute payloads from within project dependencies, potentially hiding malicious activity within seemingly legitimate library paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
304
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
204
Detects a suspicious sequence of events suggesting potential technical support scam or social engineering activity: a rapid influx of emails (email bombing) followed by an external Microsoft Teams call, and subsequently the execution of a common remote access tool on the same host within a short timeframe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
This rule detects network traffic patterns indicative of Xray-core C2 tunnels using a spoofed 'dl.google.com' TLS SNI value. This activity is associated with the Aur0ra/Black Basta playbook, where Xray-core is sideloaded into legitimate processes to exfiltrate or tunnel traffic while mimicking Chrome browser TLS behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the execution of the Windows ftp.exe binary using the -s parameter (or -s"": syntax) to execute a script file. This behavior is commonly associated with attackers using LOLBAS (Living Off the Land Binaries and Scripts) techniques to execute hidden or obfuscated scripts from mounted virtual hard disks (VHD) to facilitate malicious backdoor execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
This rule detects the creation, modification, or renaming of .lnk shortcut files within the Windows Startup folders (both current user and roaming appdata). It then correlates this activity with the execution of AutoIt3.exe or processes identified as 'AutoIt' that are running scripts with .a3x or .au3 extensions, which are commonly used for persistence and execution of malicious automation scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
103
This rule detects instances where AutoIt (AutoIt3.exe) is observed performing process injection or launching suspicious binaries (RegSvcs.exe or mobsync.exe). Attackers frequently use AutoIt for process automation and to execute malicious payloads, and leveraging legitimate binaries like RegSvcs.exe is a known technique for bypassing defenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
This rule detects potentially malicious activity where an executable with an MD5-formatted name is created in the user's temporary folder, followed by the creation of a registry key with a matching MD5-formatted name in HKEY_CURRENT_USER\SOFTWARE\ within 15 minutes. This behavior is indicative of a persistence mechanism where malware drops a payload in a temp directory and sets a run or autorun registry key to ensure its execution upon logon or startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects execution of WMI or PowerShell queries by HTA, WScript, or CScript processes to gather system information such as OSLanguage, BIOS, or hardware identifiers. This behavior is indicative of environment-awareness checks used by the Casbaneiro/Ousaban banking trojan to identify sandbox or virtualization analysis environments before proceeding with the infection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the creation or modification of a file named '.Outlook' within the AppData or AppData\Roaming folders, followed by network communication to known malicious domains or IP addresses by a process other than outlook.exe within a 30-minute window. This behavior is indicative of potential malware staging or command-and-control communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects suspicious clipboard activity where the clipboard is either accessed or modified by known utility processes (e.g., AutoIt, RegSvcs) or contains patterns indicative of cryptocurrency address hijacking (e.g., Bitcoin or Ethereum addresses).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the creation or modification of a Windows service named 'ProcAuditManager' using 'sc.exe' or 'services.exe' command-line utilities, or by direct modification of the associated registry key. This activity may indicate persistence establishment or service manipulation by an adversary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects potential Casbaneiro banking trojan activity characterized by a user accessing a known Latin American banking domain via a web browser, followed within 10 minutes by a suspicious process (RegSvcs.exe or mobsync.exe) establishing an outbound network connection, which is consistent with command-and-control (C2) behavior often seen in this malware family.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream (ADS) from files. This stream is responsible for the 'Mark-of-the-Web' (MOTW) which triggers security warnings in Windows, including SmartScreen and Protected View. Adversaries use this technique to evade security controls on downloaded malicious files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
203
Detects instances where the suspicious binary 'x47_bot.exe' performs process injection or hollows a process, followed by an attempt to gain or elevate privileges (such as via UAC bypass, token manipulation, or privilege checking) on the same host within a 15-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects non-browser processes accessing sensitive browser-stored credential and cookie databases concurrently with access to Discord local storage, which is a common behavior of information-stealing malware (e.g., x47.c) to aggregate credentials for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
avatar
Arnold Chan@slaz
avatar
SlimKQL
21 days ago
308
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
000
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
000
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
000
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
000
Page 151 of 1871