Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects instances where PowerShell is executed by a Windows Script Host process (wscript.exe or cscript.exe) using common suspicious command-line arguments. This pattern is frequently used by adversaries to execute obfuscated or bypassed PowerShell scripts while attempting to hide or proxy the execution through legitimate scripting host processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the use of PowerShell to download a file named Document.pdf using Invoke-WebRequest, saving it to disk, and immediately executing it using Start-Process. This behavior is indicative of a dropper or secondary stage payload execution pattern.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the use of PowerShell to delete files with common script or shortcut extensions from directories frequently used for persistence or staging malicious payloads, such as APPDATA, ProgramData, and the Startup folder.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of PowerShell scripts containing specific obfuscation or encoding patterns. The rule identifies potential malicious intent by searching for hardcoded suspicious strings or common binary-to-string conversion methods used to hide script content from security monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
103
Detects potential Remus infostealer activity by monitoring unauthorized processes accessing AI agent credential directories (Claude, Cursor, OpenCode, Codex) or cryptocurrency wallet files, specifically when combined with .lnk shortcut file access behavior.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
103
Detects suspicious process injection attempts into browser processes (e.g., chrome.exe, msedge.exe) characterized by direct NT API syscall invocation (e.g., NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx) originating from a non-browser parent process. This behavior, often associated with the Remus infostealer, bypasses standard user-mode API hooking by using direct syscall stubs to chain injection actions.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
003
Detects the creation or access of .pst files by processes other than standard email clients (Outlook) or web browsers. This activity is often associated with the staging and collection of sensitive email data, which could indicate credential theft or data exfiltration attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
103
Detects command execution patterns consistent with the ClickFix attack technique, where users are socially engineered into pasting and executing commands (often via the Windows Run dialog or web browsers) to bypass fake CAPTCHA prompts. The rule looks for common living-off-the-land binaries (powershell.exe, cmd.exe, etc.) spawned from browsers or explorer.exe executing suspicious downloader/execution cmdlets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
203
This rule monitors for suspicious activity related to Component Object Model (COM) objects, including registry modifications (creation, setting, or checking of specific CLSIDs related to shell links or WMI locators) in conjunction with process-level alerts (such as Remote Thread API calls, primary token modification, or WMI activity). It specifically filters out known benign system processes to focus on anomalous behavior that may indicate COM hijacking, persistence, or lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
003
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
103
The following analytic identifies the `finger.exe` utility being spawned with a command line containing an `@` character, indicating a remote host/server was specified.
The Finger protocol utility is largely obsolete in modern environments and has been abused by adversaries as a living-off-the-land binary (LOLBIN) to retrieve encoded payloads or establish covert command-and-control communication with an attacker-controlled finger server.
This behavior is uncommon in legitimate enterprise usage and warrants investigation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
18 days ago
503
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
003
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
103
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
003
Detects Network, File, or Process events associated with known C2 IOCs
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
003
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
003
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
003
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
903
This rule detects when the Node.js runtime process (node.exe) initiates the Windows command interpreter (cmd.exe) with the '/c' flag, which is commonly used to execute commands or scripts. This behavior is frequently associated with malicious Node.js activity, such as Remote Access Trojans (RATs) or web shells, which may use the shell to execute system-level operations or bypass typical application constraints.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
003
ChainScript file manager 'files' task: node.exe performing high-volume recursive deletion within masqueraded ChainScript installation paths (drive enumeration, dir listing, file read/write, recursive delete)
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
003
Page 165 of 1871