Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects hosts exhibiting multiple distinct file-manipulation commands (upload, download, stop, delete, append, copy, move) within a single session as identified by the PivotPipe C2 protocol, indicating potential staging, collection, or exfiltration activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, no profile, or encoded commands) spawned directly from a web browser process (e.g., Chrome, Edge, Firefox, Explorer). This behavior is characteristic of ClickFix-style social engineering attacks where a user is tricked into copying and executing malicious PowerShell commands via the Win+R Run dialog or terminal.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects a specific pattern of Windows API calls consistent with PIVOTPIPE C2 activity, involving process token impersonation (OpenProcessToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken) followed by a RevertToSelf call. The rule correlates these events within a single process, identifies artifacts related to PIVOTPIPE loader/payloads, and ensures the sequence completes within a short time window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects instances where npm.exe or node.exe initiate child node.exe processes, a behavior commonly associated with multi-stage loaders or malicious packages (e.g., GHAPPIER) that execute arbitrary JavaScript payloads during package installation or execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects unauthorized access, creation, or modification of Git credential files (.git-credentials, .netrc) by processes other than standard Git credential management utilities. It also monitors command-line activity that references these credential stores to identify potential attempts to exfiltrate or manipulate stored credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects the creation of multiple suspicious files within the \Windows\Temp\nb_ directory. The monitored filenames, such as 'agent.json', 'pk.der', 'sleepmask.o', and 'core.pak', are highly characteristic of post-exploitation toolkits, specifically those associated with beaconing, shellcode injection, or modular C2 agents. Detecting these files in temporary locations, especially when appearing in combination, strongly indicates potential adversary activity involving the staging and execution of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the creation of specific file artifacts and process execution associated with the PIVOTPIPE .NET loader. The rule monitors for the creation of temporary working directories prefixed with 'nb_' in '\Windows\Temp\', the staging of associated configuration and payload files (such as 'agent.json', 'pk.der', 'sleepmask.o', 'core.pak'), and the execution of associated process names like 'netbeacon_pivot.exe', 'pivot_hop2_kasp.exe', or 'x64beacon.exe'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the creation or modification of known PIVOTPIPE loader artifacts, specifically the 'sleepmask.o' file and related configuration or helper files ('agent.json', 'pk.der', 'core.pak'), within temporary directories prefixed with 'nb_' under the Windows Temp folder. These files are used by the PIVOTPIPE loader to implement sleep-masking techniques that encrypt beacon memory during dormant periods to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects PowerShell execution containing multiple command-line arguments indicative of environment discovery, such as checking system uptime, hardware specifications, or specific memory-related delays. These patterns are commonly used by malware to detect virtual machines, sandboxes, or analysis environments to alter execution or exit.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects suspicious PowerShell activity involving compression commands (e.g., Expand-Archive) within APPDATA, correlated with the execution of hypersnap.exe with hidden window arguments, and the creation of persistence via scheduled tasks. This pattern is indicative of automated staging or malicious tool execution and persistence setup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects a scenario where a single initiating process terminates multiple distinct processes within a short timeframe (5 minutes). This behavioral pattern is often associated with security tool tampering or EDR-evasion techniques where malicious code attempts to identify and terminate defensive security processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the creation of specific debug log files by PIVOTPIPE Cobalt Strike-compatible payloads in the Windows temporary directory. These artifacts indicate active post-exploitation activity, specifically operations involving process token manipulation or impersonation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule monitors for suspicious process behaviors and module loads, specifically focusing on unusual explorer.exe parentage, the loading of common system DLLs (dbghelp.dll, Secur32.dll) in potentially anomalous contexts, and specific command-line strings that may indicate malicious activity or tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects high-frequency calls to the VirtualProtect API where memory protections are changed to read/write (PAGE_READWRITE) or executable read/write (PAGE_EXECUTE_READWRITE). This behavior is often indicative of process injection techniques or self-modifying code associated with unpacking, loading shellcode, or tampering with process memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects anomalous, high-frequency interaction with the Windows clipboard by explorer.exe. This activity is often associated with unauthorized data collection or exfiltration attempts by malware residing within or masquerading as the Windows shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the loading or installation of a driver file identified as DCRCVDrv.sys followed within 5 minutes by EDR sensor heartbeat loss or process activity, which is characteristic of attempts to tamper with security software or hide malicious activity via a kernel-mode driver.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
203
Detects process execution patterns and DNS requests associated with the GHAPPIER malware staging infrastructure. The rule monitors for specific command-line arguments involving known malicious scripts, temporary files, and deployment infrastructure (e.g., Vercel) often used for delivering or executing malicious payloads via node.js environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
303
Detects a process that deletes its own executable file immediately after launching. This anti-forensic behavior is commonly utilized by remote access trojans (RATs) and other malware to minimize their footprint and evade file-based forensic analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects malicious JavaScript/npm payloads that attempt to evade static analysis and string-based detection signatures by dynamically reconstructing sensitive strings at runtime using V8 string-object construction or obfuscated string tables.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects execution of code using indirect syscalls or ntdll unhooking techniques, often associated with the PIVOTPIPE loader/RAT. The rule monitors for EDR indicators of evasion such as syscall stub execution, direct/indirect Nt* system call invocation, or call stacks originating outside of ntdll.dll, intended to bypass userland security hooks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of PowerShell with suspicious command-line arguments (e.g., WebClient, hidden flags, or WebDAV paths) spawned directly from browser processes like chrome.exe or msedge.exe. This pattern is commonly associated with fileless delivery techniques where an attacker attempts to download and execute scripts directly from an internet-facing source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Page 170 of 1871