Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects a suspicious multi-stage PowerShell execution pattern where an initial process, such as explorer.exe or common loaders, invokes PowerShell with obfuscated or download-related flags (e.g., -enc, IEX, DownloadString), followed immediately by a child PowerShell process performing further download or network operations within a short time window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
This rule monitors for processes that are digitally signed by 'Discord Inc.' or 'Lenovo' but executing from file paths that are not associated with legitimate installations of their software. This behavior is indicative of threat actors using stolen or compromised code-signing certificates to bypass security controls like SmartScreen or endpoint antivirus solutions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the launch of client32.exe (a core component of NetSupport Manager) as a child process of PowerShell, indicating potential malicious deployment of the software as a RAT rather than legitimate administrative activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects the suspicious copying of a Chromium-based browser 'Web Data' file (which stores sensitive information like saved passwords, credit cards, or address data) to a temporary file, followed by an outbound network connection to a specific exfiltration endpoint pattern within a 30-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
101
Detects a suspicious sequence where a Python process is spawned by a 'marimo' notebook process, followed immediately by an outbound SSH connection attempt from the same device. This pattern is indicative of automated or scripted lateral movement where a notebook environment is abused as a jump-point for command execution on remote systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where PowerShell, cmd, or mshta are launched as child processes of browser applications or Windows Explorer, often associated with 'ClickFix' or other social engineering attacks where a user is tricked into pasting malicious commands into the Windows 'Run' dialog. The rule identifies suspicious command-line arguments typical of downloader cradles or obfuscated scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to delete volume shadow copies, clear backup catalogs, or disable system recovery features, which is a common behavior of ransomware before encrypting files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
This rule detects scenarios where common web browsers (e.g., chrome.exe, msedge.exe) spawn known living-off-the-land (LotL) binaries (e.g., powershell.exe, wscript.exe, mshta.exe) with command-line arguments indicative of malicious activity, such as base64-encoded strings, hidden window flags, or remote script invocation (IEX/Invoke-Expression). This pattern is frequently used in drive-by download or phishing delivery chains where an initial payload is triggered directly from a browser context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
301
Detects instances where mshta.exe is launched from a web browser or explorer.exe with suspicious command-line arguments, such as remote URLs, script protocols, or potentially obfuscated/base64-encoded strings, often indicative of 'ClickFix' social engineering attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the execution of WinRAR utilities (WinRAR.exe, Rar.exe) with suspicious command-line arguments typically associated with data staging, archiving, or encryption. The rule filters out legitimate WinRAR installations and only triggers when the process is spawned by a script interpreter (e.g., PowerShell, CMD) or operates within sensitive file paths (e.g., Users, Shares, Finance, HR, Backup).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
This rule detects a single host performing a high volume of connection attempts to internal IP addresses across standard management and file-sharing ports (SMB 445, RDP 3389, WinRM 5985) within a 5-minute window. Such behavior is characteristic of network scanning or reconnaissance activities performed by adversaries attempting to identify targets for lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
This rule detects processes other than known web browsers (Chrome, Edge, Firefox, Brave, Opera) accessing sensitive browser-related files (Login Data, Cookies, Web Data) and initiating an external network connection within 15 minutes. This behavior is highly characteristic of credential and session cookie theft, often utilized by info-stealing malware for subsequent session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
102
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
Detects the use of the sc.exe command-line utility to stop or disable the Microsoft Defender Antivirus service (WinDefend). This activity is often associated with ransomware, such as Nova ransomware, to bypass security controls prior to malicious encryption or data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects attempts by malicious software to inhibit system recovery by deleting Volume Shadow Copies. The rule monitors for the execution of vssadmin.exe with deletion flags or wmic.exe with shadowcopy deletion commands combined with non-interactive flags, which are common indicators of ransomware preparation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects attempts by malicious software to inhibit system recovery by deleting Volume Shadow Copies. The rule monitors for the execution of vssadmin.exe with deletion flags or wmic.exe with shadowcopy deletion commands combined with non-interactive flags, which are common indicators of ransomware preparation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
201
Detects unauthorized processes accessing the 'ConsoleHost_history.txt' file across user profiles. This behavior is indicative of ransomware operators or malicious actors attempting to harvest stored credentials, tokens, or sensitive command-line history before performing lateral movement or privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the use of PsExec to remotely execute binaries on target hosts, a technique observed in The Gentlemen ransomware lateral movement phase when domain controller access is unavailable. The rule identifies psexec.exe process creation with common flags (-s, -d, -c) while filtering out common administrative parent processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
Detects the use of PowerShell Set-MpPreference commands to disable multiple Microsoft Defender security features, including real-time monitoring, behavioral scanning, and threat detection actions. This activity is consistent with ransomware behavior, such as Nova or The Gentlemen families, attempting to neutralize endpoint protection before proceeding with malicious actions like file encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
201
Detects the use of PowerShell to modify Microsoft Defender exclusion paths by adding root drive letters or temporary directory paths. This behavior is indicative of defense evasion techniques often employed by ransomware families, such as Nova or Gentlemen, to prevent the scanning of files immediately prior to encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
301
Page 156 of 1871