Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects Node.js processes spawning common system discovery utilities such as systeminfo, wmic, or uname. This behavior is indicative of a post-compromise scenario where a web application or Node.js-based service is being used to gather information about the underlying operating system environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects the launch or execution of common remote access tools such as AnyDesk, TeamViewer, Quick Assist, or Microsoft Remote Assistance (msra.exe) on an endpoint, excluding instances where these tools act as the parent process. This rule serves as one component of a broader detection chain for potentially unauthorized remote access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
606
This rule detects potentially malicious activity involving Node.js modules. It monitors for the deletion of specific 'sharedLoad.min.js' or 'extended' files within 'node_modules' directories, the execution of Node.js processes attempting file deletion operations (like 'unlink' or 'rm') within 'node_modules', and the creation or modification of JavaScript files within 'node_modules' that contain 'btree' references. This activity may indicate an attempt to tamper with application dependencies, inject malicious code, or remove artifacts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects the execution of AnyDesk within a 30-minute window of Microsoft Teams activity on the same device. This pattern is indicative of a vishing attack, where a malicious actor lures a victim into installing remote access software during a fake technical support session initiated via Teams.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects instances where a Node.js process spawns a child process, also running as node.exe, that attempts to execute a specific JavaScript file path (sharedLoad.min.js or its extended version). This behavior is characteristic of certain Node.js-based applications or potentially malicious scripts using shared loaders for modular execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects instances where the Node.js process (node.exe) is executed with a command-line argument referencing 'sharedLoad.min.js'. This is often used in web-based applications or potentially malicious obfuscated scripts, but may flag legitimate JavaScript automation tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
303
Detects the execution of the AnyDesk remote support application when initiated from a web browser (msedge.exe) or the Windows file explorer (explorer.exe). This pattern is often indicative of user-driven execution, potentially as part of a tech support scam or unauthorized remote access attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
303
Detects the installation of specific known malicious NPM packages (indexed-btree, btree-core, mutex-forge) or execution of npm install commands targeting these packages, which are indicative of software supply chain compromise attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects a Node.js process deleting specific core application files, such as 'index.js' or 'sharedLoad.min.js', located within 'node_modules' directories. This activity may indicate malicious tampering, package integrity compromise, or an adversary attempting to disrupt application functionality.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects instances where the legitimate remote desktop application AnyDesk (AnyDesk.exe) acts as the parent process to spawn a Windows command shell (cmd.exe) or execute a batch script (.bat). This behavior is often indicative of unauthorized remote access or the execution of malicious payloads by adversaries leveraging remote support tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects the modification of InProcServer32 registry keys within the user's Classes/CLSID hive to point to a file located in the AppData directory. This pattern is commonly used for COM hijacking to achieve persistence or execute arbitrary code under the user's context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
This rule detects network connections or DNS requests to domains specifically structured to impersonate MFA registration, passkey setup, or SSO login pages. These domain patterns are commonly associated with phishing campaigns intended to harvest credentials, session tokens, or bypass multi-factor authentication (AiTM phishing).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects the loading of wkspbroker.exe or radcui.dll modules from the Microsoft RemoteApp Gateway directory located within the user's AppData path. This behavior may indicate an attempt to utilize or manipulate Remote Desktop components from a non-standard or user-writable location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects a sequence of events where a user is targeted by an email bombing attack, subsequently receives an external or anonymous Microsoft Teams call, and finally launches a known remote access tool (e.g., AnyDesk, TeamViewer) on the same host within a one-hour window. This pattern is consistent with social engineering campaigns designed to trick users into providing remote access to their systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects the execution of AnyDesk or its installation from common user-writable directories (Downloads or AppData), as well as scenarios where a browser (msedge.exe) initiates an AnyDesk-related download. This is a common indicator of unauthorized remote access tool deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
103
Detects Node.js process executions that involve loading a suspicious JavaScript file named 'sharedLoad.min.js' or 'extended/sharedLoad.min.js'. The rule further flags instances where the process command line includes 'detached' and 'windowsHide' arguments, which are frequently used to execute Node.js scripts in the background without a visible window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects instances where a Node.js process (node.exe) attempts to execute native system discovery commands such as systeminfo, hostname, or wmic queries. This pattern is commonly observed in malicious Node.js applications or compromised environments attempting to gather system reconnaissance information.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
003
Detects the execution of MSBuild.exe with command line arguments pointing to project files (.xml or .csproj) that contain C# inline task structures (e.g., CodeTaskFactory, UsingTask). This technique is commonly used to proxy malicious code execution via a trusted Microsoft binary, bypassing certain application control policies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects instances of rundll32.exe being executed with command line arguments that point to DLLs in common user-writable or non-standard directories (e.g., Temp, AppData, Downloads, ProgramData) or employing known malicious command patterns like Control_RunDLL, javascript: protocol handlers, or shell32.dll proxy execution techniques often used to evade security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Detects msiexec.exe execution with flags intended for silent or standard installation when the source path points to a remote web resource (HTTP/HTTPS) or a UNC path. This behavior is indicative of using the native Windows Installer to proxy the download and execution of arbitrary, potentially malicious, MSI packages.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
001
Page 175 of 1871