Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation of a .bat file in the Windows Startup directory, followed by the execution of a command process from a temporary location using a specific command line pattern. This behavior is indicative of persistent malware or a dropper attempting to execute an initial payload upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule monitors for two potentially suspicious activities on Windows systems: the creation of scheduled tasks named 'MicrosoftEdgeUpdateTask' or 'MicrosoftEdgeUpdateTaskCore' using 'schtasks.exe', and the execution of scripts via 'wscript.exe' with silent flags ('//B' and '//Nologo'). These behaviors are often associated with persistence mechanisms or the execution of obfuscated/malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects a coordinated attack sequence where a browser process is terminated, followed immediately by the execution of an unsigned Python interpreter from a suspicious location (temp/downloads folder), which is then followed by the installation of an unsigned browser extension. This pattern mimics ClickFix and browser-based RAT lure campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects unauthorized processes attempting to read or modify Discord's local storage leveldb files, which store user authentication tokens, and correlates this with suspicious network activity to Discord's API or the presence of token-stealing keywords in command-line arguments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects potential usage of Hidden VNC (hVNC) tools by monitoring for specific command-line arguments (such as 'hvnc-input', 'hvnc-desktop', or 'HVNC_Telegram') and Windows events related to the creation or switching of desktops (e.g., 'CreateDesktop', 'SwitchDesktop'). hVNC is a common technique used by malware to establish a hidden remote desktop session for unauthorized access and control without alerting the user.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the installation or loading of a non-standard kernel driver followed by the termination of known security/EDR agent processes. This behavior is indicative of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where attackers leverage kernel-level privileges from a vulnerable driver to bypass EDR protections and disable security tools prior to encryption or other malicious activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects a suspicious pattern of mass security process termination, where a process masquerading as legitimate consumer or gaming software (e.g., Kaspersky, Valorant, Javelin) repeatedly uses commands like taskkill, sc stop, or NtTerminateProcess to disable EDR agents and antivirus software within a short time window. This behavior is indicative of pre-ransomware staging activities used by threat actors.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects a suspected ransomware double-extortion sequence: the bulk creation of password-protected archives using compression utilities (e.g., 7z, RAR), followed by significant outbound network connections to common cloud storage or anonymization endpoints, and concluding with mass file modifications indicative of encryption activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects unauthorized, unsigned processes accessing sensitive browser files (Cookies, Login Data, Local State) across common browsers (Chrome, Edge, Brave, Firefox) followed by an outbound network connection. This behavior is indicative of credential-harvesting infostealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
Detects instances where the Windows Package Manager (winget.exe) initiates potentially suspicious child processes such as command shells or administrative tools, and correlates this activity with network connections originating from those child processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
203
Detects a multi-stage process execution chain beginning with common end-user applications (browsers, Office apps, explorer.exe) spawning known LOLBins (Living-off-the-Land Binaries), which in turn execute secondary LOLBins with suspicious command-line indicators. This pattern often signifies post-exploitation activity such as secondary payload delivery, fileless malware execution, or proxy execution of malicious scripts/commands, consistent with ClickFix or BYOVD-related ingress techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
000
This rule detects the suspicious creation or modification of local user accounts (e.g., 'svc_ipurple') occurring within a short 15-minute window following the execution of Windows Package Manager (Winget) configuration tasks. This behavior may indicate an attacker using automated configuration files (DSC) to establish persistence or escalate privileges on a compromised system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects MSBuild.exe establishing a network connection to a specific remote IP address (212.34.141.103) on port 4521. This behavior is indicative of MSBuild being used to proxy execution of malicious code, often associated with downloading and executing second-stage payloads or beaconing to a command-and-control (C2) server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects the loading of the 'Microsoft.Management.Configuration.dll' module by specific Windows system processes involved in package management and configuration, namely 'ConfigurationRemotingServer.exe' and 'WindowsPackageManagerServer.exe'. While these are legitimate components of the Windows Package Manager and DSC services, monitoring this activity can establish a baseline for identifying potential process injection or unauthorized library loading within these security-sensitive management binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule monitors for suspicious activities involving digital certificates. It detects PowerShell processes attempting to import a certificate into the Root store, which could indicate persistence or credential interception, and it detects the use of curl to download files named 'cert.pem' with insecure SSL settings (no certificate verification).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
203
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
303
Detects instances where Windows Terminal (WindowsTerminal.exe) is launched by Explorer and immediately spawns a shell process (PowerShell, PWSH, or CMD), specifically excluding devices that have recorded recent RunMRU registry history. This pattern may indicate suspicious or non-interactive execution by an adversary attempting to bypass traditional shell history tracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects suspicious execution of the certutil.exe utility for file operations, specifically targeting the copying of certutil or the decoding of files with naming patterns (kid*.exe, kid*.tmp, kid*.bat) within the \Users\Public\Downloads\ directory. This pattern is commonly associated with file staging and deobfuscation of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects instances where PowerShell scripts perform Base64-encoded operations related to cryptographic functions and shortly thereafter establish network connections to known or suspect domains associated with C2 activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects ClickFix-style social engineering attacks where users are lured to 'cloudrobots.cloud' and subsequently execute malicious commands via Windows shell tools (cmd, powershell, mshta, etc.). The rule correlates browser network events to a specific domain, subsequent process launches by explorer.exe, and suspicious registry modifications associated with the Windows RunMRU, which is often abused to store and execute commands pasted by victims.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Page 163 of 1871