Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
002
This rule detects potential malicious activity by monitoring for known indicators of compromise, including specific SHA256 file hashes, a known malicious IP address, and URLs associated with identified threats. The detection spans file creation/execution, network connections, and URL visits to block or alert on interactions with suspicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
002
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
102
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
002
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
002
Detects execution chains associated with the SideCopy threat group's ReverseRAT payload. The detection looks for mshta.exe being spawned by common shell processes (explorer, wscript, cmd, powershell) to execute remote HTA content or access 'docsportal.in'. It also monitors for subsequent reflective DLL loading via rundll32.exe or regsvr32.exe, which is indicative of the final ReverseRAT payload activation.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
17 days ago
002
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
17 days ago
002
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
17 days ago
002
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
002
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
20 days ago
205
Detects instances where the process 'GRrte.exe' forcefully terminates 'iediagcmd.exe' using taskkill.exe. This activity is indicative of an attempt to disable or impair specific security diagnostic tools or EDR-related components on the host.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
20 days ago
305
Detects non-browser processes performing file operations (create, modify, rename) on known web browser credential storage, configuration files, and cryptocurrency wallet artifacts in a short duration. This behavior is indicative of credential harvesting or information stealing activity often associated with malware like Vidar, which stages these sensitive files for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
102
Detects rapid, closely-spaced network requests from the Microsoft Edge process (msedge.exe) to Microsoft-hosted domains within a very short timeframe. This behavior is indicative of a race-condition exploitation technique (CVE-2026-55945) intended to manipulate the Edge AI agent's state transitions, specifically forcing it from 'think' mode into 'act' mode to facilitate unauthorized command injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
508
This rule detects the execution of a malicious PowerShell command chain initiated by explorer.exe, consistent with the PlugX malware infection sequence. The detection monitors for specific command-line arguments, including the use of curl for file downloads, tar for extraction, and the launching of associated malicious executables like 'GRrte.exe' following the execution of a shortcut file named 'OIC_Invitation_General_Official.lnk'.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
20 days ago
305
Detects suspicious remote registry operations performed through the Winreg RPC interface. The rule monitors for interactions with sensitive registry hives (e.g., SAM, SECURITY, SYSTEM) or anomalous levels of remote registry activity originating from remote connections (SMB, TCP, Named Pipes). Such activity is often associated with credential dumping tools like Impacket's secretsdump or unauthorized remote configuration discovery.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
20 days ago
104
Page 178 of 1871