Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,173 detections

Detects a multi-stage activity where PowerShell is used to download a ZIP file, followed by the execution of a batch script (1.bat) that subsequently launches LockScreenContentServer.exe. This behavior is indicative of a DLL side-loading chain designed to execute malicious code via legitimate processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
This rule detects instances where a process matching a known sideload-vulnerable binary (such as werfaultsecure or wuauclt) spawns a PowerShell process that executes commands commonly used for Active Directory reconnaissance and system information discovery. This behavior is indicative of post-compromise activity, specifically reconnaissance phases performed by malware loaders like Lorem Ipsum.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
Detects instances where the IIS worker process (w3wp.exe) spawns the Windows command shell (cmd.exe) to execute common reconnaissance commands such as whoami, hostname, systeminfo, and net user. This behavior is strongly indicative of post-exploitation activity following a successful web shell deployment on a web server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
002
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
003
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
406
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
003
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
003
Detects outbound network connections to common TOR entry, guard, or client service ports, or the execution of TOR-related processes. This behavior may indicate an adversary establishing C2 communication channels or attempting to perform anonymized data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
003
Detects instances where a process contacts multiple distinct AI-provider domains within a short time frame while simultaneously performing suspicious operations, such as accessing the LSASS memory, executing process injection, or establishing WMI persistence. This pattern is indicative of a potential 'ClosedQuorum' adversary behavior involving data exfiltration or AI-assisted malicious activity.
chris tano@christano
avatar
Detections.ai Community
11 days ago
007
Detects anomalous process execution by PeopleSoft application server processes (e.g., psappsrv, jsvc) immediately following an inbound network request. This behavior is indicative of exploitation of a Java deserialization gadget chain, such as those used by the threat actor UNC6240 to achieve Remote Code Execution (RCE) and spawn command interpreters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
003
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
103
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
003
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
101
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
101
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
001
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
101
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
101
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
Page 16 of 1866