Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the presence of specific ysoserial gadget chain strings (ActivitySurrogateSelector/ActivitySurrogateDisableTypeCheck) indicative of deserialization attacks targeting Microsoft SharePoint via System.Web.UI.LosFormatter. This typically occurs in memory within w3wp.exe processes following an initial RCE exploit, such as those targeting EditingPageParser or ToolPane.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the presence of ZIP archive files masquerading as 'Evernote.zip' that contain 'notepad++.exe', which is a pattern frequently observed in VBScript-based downloaders utilizing binary sideloading to execute malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects signs of Zerologon (CVE-2020-1472) exploitation by correlating Netlogon (MS-NRPC) authentication anomalies involving known exploitation tools/process names with subsequent machine-account password reset events (Event ID 4742) occurring on the same device within a short time window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the use of WScript or CScript to query the Win32_OperatingSystem WMI class for the InstallDate property. This behavior is commonly used by malware to identify the system installation time, which can serve as a simple heuristic for sandbox evasion or environmental keying.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the creation of files on a host system that match naming conventions consistent with Rhysida ransomware notes. These files (e.g., README, HOW_TO_RECOVER) indicate a post-encryption state where the adversary has demanded payment. The detection joins events to highlight multiple occurrences of these note-like files on a single device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects anomalous, mass-access behavior targeting plaintext credential files, certificate stores, private keys, or password-manager databases located on general-purpose network shares. Such activity is often indicative of an adversary conducting discovery or collection of credentials for lateral movement and privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where PowerShell is initiated via LNK files, specifically targeting PDF LNK attachments or known malicious script naming patterns (update1.vbs, update2.ps1) and common downloader cmdlets (e.g., IEX, Invoke-WebRequest). It also includes specific indicators for remote file downloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the deletion of .zip files within the Public directory by VBScript or JScript interpreters (wscript.exe or cscript.exe). This pattern is often indicative of a malicious dropper or downloader that extracts a payload from a staged archive and subsequently removes the evidence to hinder analysis and forensics.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the execution of a .vbs script file that contains '.pdf' in its filename, followed within 5 minutes by the execution of a WMI query via wscript.exe. This behavior is indicative of a malicious VBScript dropper attempting to perform system discovery using WMI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects the execution of Windows Script Host (wscript.exe/cscript.exe) loading WMI-related modules (wbemprox.dll, wbemcomn.dll, etc.). This pattern is often indicative of scripts attempting to query WMI for system information, environment configuration, or locale data, which is a common reconnaissance technique used by malware to identify the victim environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the execution of a .vbs script file that contains '.pdf' in its filename, followed within 5 minutes by the execution of a WMI query via wscript.exe. This behavior is indicative of a malicious VBScript dropper attempting to perform system discovery using WMI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where wscript.exe deletes a .zip archive from within the C:\Users\Public\ directory structure. This activity is frequently associated with VBScript droppers performing anti-forensic cleanup by removing staged payloads after extraction but prior to execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects the execution of script files (such as .vbs, .vbe, .js, .jse) via wscript.exe when the file name uses a double-extension technique (e.g., .pdf.vbs) to masquerade as a benign PDF document. These files are typically found in temporary or user-download directories, indicating potential malicious activity initiated by downloaded attachments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the execution of wscript.exe or cscript.exe with a command line containing a .vbs file, occurring within a 5-minute window of the creation of a file named 'notepad++.exe' or 'readme.txt' within a sub-directory of 'C:\Users\Public\'. This behavior is indicative of a potential multi-stage execution where a script is used to drop or interact with files in public-accessible folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects potential malicious VBScript behavior where the script queries system language settings via WMI and subsequently launches a decoy message box commonly associated with initial-stage malware loaders or droppers to deceive users before initiating a payload download.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where a command-line utility or scripting interpreter references a 'SKILL.md' configuration file, typically associated with agent-skill payloads, followed shortly by network-based file download activity. This behavior is indicative of a secondary payload retrieval triggered by an adversary-controlled or poisoned configuration file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the execution of the Chisel C2 tool by matching its unique command-line grammar, specifically the 'client' subcommand combined with reverse remote ('R:') configurations. This detection strategy is resilient against binary renaming and infrastructure rotation by focusing on the tool's required argument structure rather than static IOCs like filenames or C2 addresses. It is specifically useful for identifying unauthorized remote tunnels used for persistence and data exfiltration.
avatar
Tim Peck@timpeck
avatar
SecOps Signals
24 days ago
8017
Detects instances where the Claude Desktop application spawns a terminal or shell process that immediately executes commands associated with downloading remote payloads or accessing sensitive cryptocurrency wallet artifacts. This behavior is indicative of potential AI prompt injection where an AI assistant is coerced into executing malicious commands without user authorization.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the abuse of the DFS Namespace Management (DFSNM) interface by monitoring calls to NetrDfsAddStdRoot (opnum 12) and NetrDfsRemoveStdRoot (opnum 13). An adversary can trigger these functions to coerce a Windows host to authenticate to an attacker-controlled remote host using NTLM, facilitating NTLM relay attacks.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
14 days ago
101
This rule detects when the MpDlpService.exe process loads the 'mpclient.dll' library from a location other than the legitimate Windows Defender program directories. This behavior is indicative of potential DLL side-loading or hijack execution flow attempts targeting the Microsoft Data Loss Prevention service.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
14 days ago
101
This rule detects potential staging activity for ClickFix or Vidar malware campaigns. It identifies the creation of files or folders in directories mimicking Windows Diagnostics infrastructure (WDI) or known payload paths, correlated with the execution of suspicious PowerShell commands or archive-related utilities within a 30-minute window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
14 days ago
001
Page 154 of 1871