Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
101
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
101
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
Detects the execution of control.exe with suspicious command-line arguments involving WebDAV paths (DavWWWRoot) and file extensions like .cpl or .dll, initiated by Windows task-related processes (svchost, taskeng, schtasks). This pattern is indicative of potential malicious payload loading or proxy execution where a scheduled task is used to trigger a secondary malicious component.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
101
Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
11 days ago
206
Detects wscript.exe or cscript.exe executing a VBScript that uses MSXML2.XMLHTTP and ADODB.Stream to download a file in chunks (using the Range header) to a temporary or AppData location. This technique is often used by malware to evade detection by downloading payloads in smaller pieces.
avatar
Luís Marques@remotecodeexecution
avatar
SIBS Cyberwatch
7 days ago
002
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
003
This rule detects a sequence of events characteristic of the x47.c persistence pattern. It monitors for the creation of persistence mechanisms via Windows Registry Run keys or scheduled tasks, followed by the addition of Windows Defender exclusions using PowerShell within a 30-minute window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
205
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
005
This rule detects potential persistence via scheduled tasks that masquerade as legitimate network components (e.g., 'System Health Monitor'), as well as abnormal use of WebDav via rundll32.exe or net.exe in the context of the Star Blizzard (COLDRIVER) campaign. It monitors for task creation/updates, schtasks command lines, registry artifacts related to task scheduling, and suspicious WebDav network utility usage, while excluding common security tool processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
003
This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
403
This rule detects potential post-compromise activity related to a campaign using MSP360-masqueraded installers and ScreenConnect remote access tools. It performs an IOC sweep across device file events for known malicious file hashes (associated with installers and post-compromise utilities) and device network events for connections to known malicious domains used for command and control.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
003
Detects execution of potentially malicious or dual-use tools (such as credential dumpers or security-bypass utilities) from within ScreenConnect temporary directories via the 'RunFile' command. This is indicative of an attacker leveraging legitimate remote support software to deploy secondary payloads.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
103
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
103
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
103
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
103
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
104
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
204
This rule detects suspicious persistence activity involving known tools or names that are often masqueraded. It looks for the creation of registry run keys or scheduled tasks using names associated with common tools ('Canon Configuration Reader', 'Stardock DeElevation Tool') when the initiating process is not located in the expected vendor-authorized directories. The rule specifically alerts on devices exhibiting these behaviors within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
004
Page 17 of 1866