Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects non-browser and non-messaging processes accessing both browser credential stores (like 'Login Data' or 'Cookies') and messaging application session storage (Slack/Discord LevelDB) in a single session. This pattern is characteristic of credential-stealing malware, such as RevStealer, which targets both saved web browser credentials and application session tokens for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
202
Detects the execution of elevated cmd.exe processes (running with High or System integrity) spawned by parent processes originating from the AppData directory. This pattern is commonly associated with malicious installers, droppers, or payload execution where a staged binary in the user profile attempts to perform administrative actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects PowerShell execution that combines screen capturing capabilities (System.Drawing.Bitmap, Windows.Forms) with network communication (System.Net.WebClient) directed towards known C2 domains (medianewsonline.com) using specific exfiltration parameters (OKey, Who).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects unauthorized processes attempting to open handles to Google Chrome or Microsoft Edge with elevated permissions, specifically accessing thread context (often associated with hardware breakpoints used for process injection or credential extraction techniques).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects unauthorized access to critical Chromium-based browser credential databases (such as Login Data, Cookies, and History) by processes other than recognized browser executables. This behavior is indicative of credential-harvesting activity, specifically matching techniques employed by infostealers like RevStealer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects suspicious process access attempts targeting common web browsers (chrome, msedge, firefox) using high-privilege access masks (such as 0x1F0FFF or 0x1FFFFF). The detection is specifically scoped to calls originating from unbacked memory (indicated by an UNKNOWN stack trace entry containing ntdll.dll), which is a common indicator of direct or indirect syscalls used by malware for stealthy memory access, such as credential theft or session cookie exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the execution of a RevStealer native PE payload by an Electron-based loader (XabivSystem.exe). The rule identifies when the loader spawns an unsigned, detached process from a hidden, randomly-named subdirectory within the user's AppData folder. This process creation is a precursor to the malware's environment checks, anti-VM/sandbox gating, and CAPTCHA verification routines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects a non-privileged user creating a new DLL file within the C:\ProgramData\CrossDevice\ directory on a system that has specific COM registration keys (CLSID {135fd325-45b7-4c30-89f8-4386961669f0} or {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}) pointing to potentially missing or hijacked InprocServer32 paths. This is a common technique used for COM Hijacking or Persistence via phantom DLL loading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the loading of an unsigned or attacker-controlled DLL into a SYSTEM-context dllhost.exe process, consistent with the exploitation of dangling COM CrossDevice CLSIDs (e.g., forcing ICreateObject::Proc3 to LoadLibrary from a C:\ProgramData location).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects instances where dllhost.exe (COM Surrogate) running under high-integrity accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) loads an unsigned DLL file located in the C:\ProgramData\ directory. This pattern is commonly associated with DLL side-loading or malicious library injection to maintain persistence or escalate privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the loading of an unsigned or attacker-controlled DLL into a SYSTEM-context dllhost.exe process, consistent with the exploitation of dangling COM CrossDevice CLSIDs (e.g., forcing ICreateObject::Proc3 to LoadLibrary from a C:\ProgramData location).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the execution of PowerShell commands that leverage specific tooling for scheduled task enumeration, commonly used for discovery or persistence management. The rule flags usage of 'Get-AccessibleScheduledTask' in conjunction with flags associated with tools like NtObjectManager or OleViewDotNet.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects non-browser processes accessing sensitive browser credential stores (e.g., Login Data, Cookies) and cryptocurrency wallet files within a short time window. This pattern is characteristic of infostealer malware like Vidar, which grabs browser and wallet data for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects web browser processes (Chrome, Edge, Firefox, Brave, Opera, IE) being spawned by a parent process that is not part of the standard, trusted application launch lineage. This pattern is commonly observed in credential-stealing malware like Vidar Stealer, which invokes browsers to access and exfiltrate stored browser data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the custom ARX-based stream cipher used by Vidar Stealer (v2.2+) to encrypt strings and configuration data. The rule identifies the presence of specific FNV-1a and golden-ratio constants used for state initialization, in combination with unique, per-build keystream constants observed in recent variants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the presence of known Vidar Stealer malware binaries (internal build versions 2.0 through 3.4) by matching their SHA256 file hashes. Vidar is an infostealer malware typically used to exfiltrate sensitive data from victim systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects a low-privileged account manually triggering the 'CreateObjectTask' scheduled task, which is a known technique to force the 'Shell Create Object Handler' (dllhost.exe) to start under the SYSTEM context. This behavior is often associated with pre-exploitation steps for privilege escalation vulnerabilities, specifically those involving OBJREF marshaling targeting specific COM objects.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
202
Detects the compiled x86/x64 fetch-decode-execute dispatch loop used by the Vidar Stealer custom VM bytecode interpreter (v2.0+). The rule identifies the structural jump-table bounds-check and computed-jump idiom that is consistent across different builds of the malware, despite randomization of opcode values and XOR keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the presence of PIVOTPIPE loader artifacts, specifically the COFF sleep-mask object file (sleepmask.o) and its associated debug log (nb_sleep_dbg.txt), which are written to a randomly named subfolder within the Windows temporary directory as part of a sleep-obfuscation evasion sequence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the creation of specific named pipes often associated with Cobalt Strike and similar C2 frameworks used for peer-to-peer (P2P) lateral movement. The detection looks for anomalous pipe names created by processes other than standard Windows system processes (svchost, services, lsass), which is a common indicator of beacon communication relaying.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
203
This rule detects potential credential theft by correlating access to local git credential files (e.g., .git-credentials, .netrc) followed by a git push event from the same user account within 24 hours. The rule flags these pushes if they originate from an unrecognized host or an IP address outside of the trusted internal network range.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Page 169 of 1871