Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

This rule detects potential DLL sideloading activity where legitimate, signed binaries (such as COTFileReadApp.exe or DeElevate64.exe) are executed from non-standard directories (e.g., AppData, Temp, Downloads) while loading specifically identified malicious or sideloaded DLLs. The detection identifies patterns where these binaries operate outside their expected vendor installation paths, indicating a likely attempt to hijack execution flow.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
1704
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
003
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
003
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
104
This rule monitors for known malicious file hashes, command and control (C2) domains, and specific download URLs associated with identified threats. It correlates these indicators across process execution, file activity, and network connection logs to identify potential compromises or malicious activity related to the aware-cr1 infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
201
This rule detects known-malicious activity associated with Warlock ransomware and the ToolShell malware campaign (linked to Storm-2603). It monitors for process, file, and image-load events matching identified malicious file hashes, as well as network connection attempts to known malicious domains and URLs. It also includes monitoring for traffic to 'oastify.com', a domain commonly used for Burp Collaborator, which requires correlation with other indicators to confirm malicious intent.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
101
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
001
Detects the execution of known cloud synchronization utilities like rclone, megasync, or megacmd, which are frequently leveraged by ransomware operators to exfiltrate data to public cloud storage providers. The rule monitors both local process execution with typical command-line arguments and subsequent outbound network connections to common cloud storage domains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
103
Detects potential exploitation attempts targeting the vulnerable Oracle PeopleSoft PSEMHUB Environment Management Hub endpoint (associated with CVE-2026-35273 and UNC6240). The rule identifies suspicious bursts of POST requests where the URI path uses percent-encoding or mixed-case characters to evade Web Application Firewall (WAF) filtering.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
006
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
001
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
001
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
001
Detects the execution of a ScreenConnect installer executable followed by the deployment or startup of its associated client components (WindowsClient.exe or ClientService.exe) within a 30-minute window on the same device. This rule is designed to identify the unauthorized installation or deployment of remote access software.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
201
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
001
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
16 days ago
11026
Detects the creation of persistence mechanisms through both Registry Run keys and Scheduled Tasks within a one-hour window, specifically targeting names indicative of masquerading as legitimate update or helper components.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
102
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
302
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
102
Page 18 of 1866