Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
301
Detects the execution of known malicious MSI files associated with the LegionLoader malware family by monitoring process creation events involving msiexec.exe. The rule matches on specific file hashes and filenames identified in technical analysis of LegionLoader variants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the loading of a known malicious 7z.dll file within the 'Traiolx Custom Utils' directory. This behavior is indicative of DLL sideloading used by LegionLoader to achieve code execution under the guise of a legitimate application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the loading of a known malicious 7z.dll file within the 'Traiolx Custom Utils' directory. This behavior is indicative of DLL sideloading used by LegionLoader to achieve code execution under the guise of a legitimate application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the presence of a suspicious or known malicious 'Normaliz.dll' file located within the 'Traiolx Custom Utils' directory, indicative of a DLL sideloading attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This behavior is often associated with malware or malicious loaders (such as LegionLoader) that use secondary instances to facilitate malicious code execution or persistence while masquerading as legitimate update utilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the installation or registration of the legitimate gitlab-runner.exe binary as a persistent Windows service. Adversaries can leverage this technique to establish a command-and-control (C2) channel or persistent backdoor by masquerading as legitimate CI/CD infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects unsigned or non-standard Python processes loading core Windows system modules like kernel32.dll or ntdll.dll. This behavior is consistent with NarwhalRAT's fileless execution technique, which utilizes ctypes to interact with low-level Windows APIs (VirtualAlloc, RtlMoveMemory, CFUNCTYPE) for in-memory payload allocation and execution, bypassing traditional disk-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the BTR.sys driver, a tool identified as being extracted from Microsoft's MpEngine.dll and repurposed for kernel-level file and registry manipulation. The rule matches on specific SHA-256 file hashes or combinations of PE metadata strings, indicating the presence of this driver on the system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule detects the creation of a new service in HKLM\SYSTEM\CurrentControlSet\Services that includes specific suspicious command-line arguments (containing ':changelist') and is configured to start automatically (Start value '1') or belongs to the 'Boot Bus Extender' group. This behavior is often associated with persistence mechanisms where adversaries register a service to execute malicious payloads upon system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of BTR_CLI.exe with command line arguments indicative of installing or interacting with the Mimikatz driver (mimidrv.sys). This behavior is associated with loading the malicious driver to facilitate credential dumping from kernel memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the creation of .bat files within the Windows Startup folder. Adversaries often use this technique to achieve persistence by ensuring a script executes automatically upon user login.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of PowerShell with suspicious command-line flags often associated with malicious scripts (e.g., hidden windows, no profile, bypassed execution policies) when the script is located in the Windows Temporary directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects instances of the Windows Character Map utility (charmap.exe) loading graphics-related libraries such as System.Drawing.dll or gdiplus.dll. These modules are typically not required by charmap.exe and their loading is a common indicator of process injection for the purpose of capturing the screen or desktop interface.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects instances where PowerShell is launched as a child process of WScript.exe or CScript.exe with suspicious command line flags intended to hide window visibility, bypass execution policies, or run in a non-interactive mode. This behavior is frequently used by adversaries to execute obfuscated or malicious scripts while minimizing user awareness.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects instances where PowerShell.exe spawns the .NET C# compiler (csc.exe) with command-line arguments referencing a '.cmdline' file. This pattern is commonly used by adversaries to compile malicious code in-memory, bypassing traditional disk-based file scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of known development, scripting, and administrative tools (e.g., Python, Node.js, GCC, Docker) from non-standard or unauthorized file paths. The rule leverages allowlists for process names, publishers, and trusted installation directories to identify potentially unauthorized usage of powerful tooling often abused by attackers for post-exploitation activities.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
2014
Detects the loading of 'opencv_world4120.dll' by specific process names commonly associated with update activity (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) when the loaded DLL is either unsigned, untrusted, or has an invalid signature. This is indicative of potential DLL side-loading where malicious code is executed under the context of an ostensibly legitimate update process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects unauthorized processes attempting to access sensitive Mozilla Firefox profile files such as cookies.sqlite, places.sqlite, and permissions.sqlite. These files contain sensitive information including cookies, history, and permission settings. Access by processes other than the legitimate Firefox executable may indicate credential theft, data exfiltration, or reconnaissance activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects suspicious processes (named UpdateAssistant.exe, AppUpdateHelper.exe, or SysMaintenance.exe) executing from specific file system paths and initiating network connections to known suspicious IP addresses (5.230.249.49, 40.124.169.27) on non-standard ports (27015, 27017). The rule correlates process execution from specific suspicious directories with network activity to identify potential command-and-control communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of suspected Hidden VNC (HVNC) backdoor components that demonstrate behaviors consistent with banking credential theft, specifically targeting keystroke logging APIs. The rule monitors for specific process names executing from suspicious directories often used for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Page 181 of 1871