Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
000
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
000
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
000
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
000
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
000
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
000
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
000
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
000
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
000
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
403
Detects the creation of 'auth_codes.json' files within directories containing 'seria' in their path. This file is known to be used to store MD5-derived 8-character hex recovery codes for Dahua devices, allowing for password bypass or recovery via the easy4ipcloud.com portal without valid credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
004
Detects the execution of PowerShell commands that utilize .NET cryptography classes (AesManaged) in conjunction with data compression (GZipStream) and base64 decoding (FromBase64String). This combination of classes is highly characteristic of malicious scripts designed to decrypt and execute obfuscated or packed payloads in memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
204
Detects an accelerated sequence of attack phases—specifically recon, privilege escalation, lateral movement, and persistence—occurring on a single device within a short timeframe (15 minutes). This behavioral pattern indicates potential automated or script-orchestrated intrusion activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects the execution of PowerShell with hidden flags and encoded commands spawned by a 'conhost.exe' process running in '--headless' mode. This specific process pattern is indicative of the obfuscated execution chain used by LausivLoader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
004
The following analytic detects the usage of wevtutil.exe with parameters for clearing event logs such as Application, Security, Setup, Trace, or System.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments.
This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
If confirmed malicious, this behavior could allow an attacker to erase evidence of their activities, making it difficult to trace their actions and understand the full scope of the compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
003
Detects malicious processes or scripts that perform multi-stage environment fingerprinting to identify virtualization or sandbox environments. The rule identifies chains of suspicious activities, including querying registry keys related to virtualization (e.g., VMware, VirtualBox, QEMU), WMI queries for BIOS/Computer system details, API calls common to sandbox evasion (GetCursorPos, GetTickCount), and artificial execution delays (sleep/timeout), typically used by malware like LummaC2 to perform conditional exits if an analysis environment is detected.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Page 161 of 1871