Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
002
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
002
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
002
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
006
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
006
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
002
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
002
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
002
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
002
Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
002
Detects creation of a token.cmd file in AppData followed by its execution via cmd.exe within a 5-minute window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
003
Detects a process that deletes its own executable or script file within a short time window after launch, which is a technique used by some implants.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
003
Detects the execution of the AnyDesk remote support tool while Microsoft Teams is currently running. This pattern is often indicative of social engineering or tech support scams where an attacker convinces a victim to run remote access software during a call.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects suspicious PowerShell commands involving node.js, hidden window styles, and file downloads or transfers.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
103
Detects the loading of radcui.dll from the non-standard %LOCALAPPDATA%\Microsoft\RemoteApp\Gateway\ directory. This behavior is associated with DLL sideloading chains where signed Microsoft binaries (such as wkspbroker.exe) are abused to load malicious payloads, often seen in the PREY-0058/Aur0ra Teams vishing campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the presence of file artifacts associated with the Xray-core proxy tool when used as an implant via DLL sideloading. The rule identifies specific files (radcui.dll, config.json, comsrv.dat, KB85809588.bat) or malicious configuration patterns indicating proxy traffic (VLESS/VMess/outbound/inbound) targeting known C2 endpoints.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects Node.js processes executing system-level reconnaissance (e.g., CPU, memory, hostname, uptime enumeration) followed by network connections to known exfiltration endpoints (Slack, Telegram API). This behavior aligns with identified npm malware campaigns using host fingerprinting for target selection and data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects the execution of the AnyDesk remote access tool shortly after its likely download via Microsoft Edge. This pattern is commonly associated with social engineering vishing attacks where an adversary directs a user to download and run remote access software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects persistence attempts using Component Object Model (COM) hijacking by modifying HKCU CLSID InProcServer32 registry keys. The rule specifically identifies instances where the registry value points to a DLL file located within the user's AppData or LocalAppData directories, excluding typical system or program directories, as seen in sideloading persistence chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the GHAPPIER loader identified across 65 public npm/GitHub repositories and 22 developer accounts, based on its embedded remote-fetch/eval pattern and campaign markers
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
003
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
003
Page 174 of 1871