Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream from a file, effectively bypassing Mark-of-the-Web (MOTW) security protections. This behavior is often associated with the 'Unblock-File' cmdlet and is used by adversaries to execute downloaded malicious files without security warnings.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects the execution of 'mshta.exe' loading an .hta file containing specific suspicious terms ('VLC', 'Presentation', 'Denver'), followed by the spawning of child processes such as 'wscript.exe', 'cscript.exe', 'powershell.exe', 'cmd.exe', or 'wmic.exe'. This pattern is frequently used to proxy execution of malicious scripts via legitimate Windows binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This pattern can indicate suspicious activity where a legitimate updater process is being misused or abused to spawn additional malicious code or side-load components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects the presence of a 7-Zip library file ('7z.dll') located within a specific 'Traiolx Custom Utils' directory. The rule flags this file based on known malicious file hashes (MD5 or SHA256) or its specific file path. This is indicative of an adversary placing custom or potentially malicious tools on a system for archive manipulation or data staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of a specific Visual Basic script named 'Telegram_Private_Call_Session.vbs' by Windows scripting utilities (wscript.exe, cscript.exe) or the Microsoft HTML Application host (mshta.exe). This pattern is often associated with the execution of malicious scripts disguised as legitimate communication application components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of a PowerShell script named 'lightlife.ps1'. The rule flags instances where this specific script is invoked with bypass execution policies or when it is initiated by script hosts like wscript.exe or mshta.exe, which are common patterns for obfuscated or secondary script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by using reflection to modify the 'amsiInitFailed' field within the 'AmsiUtils' class. This technique is commonly used by malicious scripts to disable AMSI scanning during their execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects suspicious PowerShell command lines that utilize both 'Invoke-Expression' (iex) and 'Invoke-RestMethod' (irm), often used to download and execute code directly from remote sources. The rule specifically monitors for known indicators like specific IP addresses, file paths, or the concurrent use of these cmdlets in a single command line.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects attempts to disable PowerShell Script Block Logging via registry modification or by using the Set-ItemProperty command. Disabling this security feature prevents visibility into the actual contents of executed PowerShell scripts, which is a common tactic used by adversaries to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects attempts to disable PowerShell Script Block Logging via registry modification or by using the Set-ItemProperty command. Disabling this security feature prevents visibility into the actual contents of executed PowerShell scripts, which is a common tactic used by adversaries to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the creation of scheduled tasks using schtasks.exe that are configured to run every minute, specifically targeting command lines associated with known suspicious processes like 'codeflush.exe' or potentially masqueraded music library tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects the execution of common command-line or scripting tools (cmd.exe, powershell.exe, wscript.exe, cscript.exe, ftp.exe) or .lnk file handling triggered by explorer.exe immediately following the mounting of a VHD or VHDX file. This behavior is indicative of an attacker mounting a malicious virtual disk image and executing payloads contained within it.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects Python processes (python.exe, python3.exe, pythonw.exe) loading native library files (.pyd or .so) followed by file access to sensitive browser credential and cookie storage locations (e.g., Login Data, Cookies, Local State). This pattern is characteristic of infostealer activity, where a Python script uses a native module to decrypt or extract browser-stored credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
000
Detects file creation, renaming, or deletion events within the Recycle Bin directory involving suspicious filenames or PDF files, which may indicate an adversary attempting to hide, stage, or delete evidence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule monitors for suspicious network traffic to SMTP services and specific external email addresses, as well as process command lines containing these indicators. Additionally, it tracks email events involving specific sender, recipient, and subject indicators which may be indicative of unauthorized communication or data exfiltration attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects instances where the Greenshot.exe application loads DLLs (log4net.dll, GreenshotPlugin.dll, LinqBridge.dll) from locations outside of the expected installation directory ('\Program Files\Greenshot' or '\Program Files (x86)\Greenshot'). The rule also tracks the creation of configuration or updater files ('greenshot-defaults.ini', 'updater.bat') which may be indicative of unauthorized modification, persistence, or potential DLL side-loading attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects the execution of specific suspicious batch scripts (e.g., 'bd_test_k7old.bat') via cmd.exe, or the creation of a Windows service involving kernel drivers using sc.exe, which may indicate testing of defensive mechanisms or the deployment of potentially malicious kernel-level components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects rapid execution of multiple discovery-related commands (whoami, tasklist, ipconfig, netstat, systeminfo) by common Windows host processes within a 15-minute window. This behavior often indicates an adversary performing reconnaissance after gaining an initial foothold.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of processes or creation of events attempting to mimic Windows Security credential prompts. This pattern is characteristic of the TukTuk C2 framework's 'Cred Prompt' feature, designed to harvest user credentials by presenting a fake authentication dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects instances where the Cursor IDE (or associated helper processes) spawns a child process or executes a command involving a specific 'DevOps-Automation/cloudshield' path. This monitors for potential abuse of IDE environments to trigger sensitive automation scripts, possibly indicating malicious use of IDE tooling or unauthorized development activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects signs of malicious activity involving specific files (StreamServiceSharedBridge.ps1, ComponentTask33Agent) and behaviors, including PowerShell execution, scheduled task creation, script execution via wscript, and registry run key modification. These behaviors are indicative of persistence mechanisms and potentially suspicious command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Page 164 of 1871