Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of known HVNC (Hidden Virtual Network Computing) backdoor binaries identified by specific file names and staging directory paths. These binaries are designed to create hidden desktop sessions and perform input injection to facilitate unauthorized remote control of a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects instances where the WindowsPackageManagerServer.exe (WinGet COM Server) is invoked to perform DSC (Desired State Configuration) operations (via ConfigurationStaticFunctions) by a process other than the standard winget.exe. This behavior is indicative of an attempt to bypass process-based monitoring of winget.exe by interacting directly with the COM API using custom or alternative tools like DSCourier.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the creation of a local user account and its subsequent addition to the local Administrators group via PowerShell cmdlets (New-LocalUser, Add-LocalGroupMember) triggered by the ConfigurationRemotingServer.exe process. This activity is indicative of abuse of the WinGet Desired State Configuration (DSC) 'Script' resource to establish persistent administrative access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects access or interrogation of the WinGet configuration history database (config.db) by non-standard or user-supplied Python scripts, which may indicate an attempt to enumerate installed package configurations or extract sensitive information from the local configuration state.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the WinGet DSC configuration engine spawning service management processes such as sc.exe or PowerShell to create or modify Windows services. This activity is consistent with the abuse of DSC 'Service' resources to achieve persistence or privilege escalation by registering services to run as LocalSystem.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects processes associated with the WinGet/DSC configuration engine (ConfigurationRemotingServer.exe, WindowsPackageManagerServer.exe, or winget.exe) initiating processes with the COR_PROFILER or COR_ENABLE_PROFILING environment variables. This behavior is indicative of leveraging .NET profiler hijacking via the DSC 'Environment' resource for persistence or privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the copying of the legitimate Windows curl.exe binary to a renamed filename within user-writable directories (e.g., %TEMP%) via PowerShell. This technique is often used to masquerade the utility for stealthy file downloads. The rule also identifies the execution of these renamed binaries by checking for a mismatch between the current filename and the binary's original file description embedded in its PE header.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of WinGet DSC backend services, ConfigurationRemotingServer.exe or WindowsPackageManagerServer.exe, when launched as child processes of WinGet or DSCourier. This behavior is indicative of potential proxy execution abuse where WinGet components are leveraged to execute arbitrary code or configurations via signed Microsoft binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule detects malicious .lnk files typically delivered as email attachments (spearphishing). It identifies shortcuts that execute cmd.exe with the /k switch, combined with environment variable substring expansion techniques designed to obfuscate multi-stage command execution chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the creation of files in the Windows Temp directory that match specific naming patterns associated with UnixStealer, including tool executables, database files, stolen data archives, and debug logs. These artifacts are characteristic of the tool's staging and activity tracking behaviors.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
001
Detects instances where cmd.exe spawns a powershell.exe process with the execution policy set to bypass. This is a common technique used by attackers to execute malicious scripts while bypassing local security restrictions on script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the creation or execution of a scheduled task named 'MicrosoftMusicLibrariesPackageTaskMachine' and the invocation of specific associated file names 'codeflush.exe' or 'settingenv.cat', which are indicators of persistence used by the threat actor APT37.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
102
Detects the copying of the legitimate Windows curl.exe binary from System32 to a user-writable directory (such as AppData\Local\Temp) and renaming it. This is a common LOLBin (Living Off the Land Binary) technique used by adversaries to disguise the utility as a benign application to evade detection while facilitating the download of second-stage payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the use of the Windows command shell 'copy' utility to concatenate separate files, such as 'header.doc' and 'body.doc', into an executable file named 'Windowsupdate.exe'. This technique is commonly used by adversaries to reassemble malicious payloads that were split to evade signature-based detection or bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects network beaconing activity associated with the Casbaneiro (Metamorfo) banking trojan. The rule monitors for specific C2 communication patterns, including the 'client;' string and the 'VVx-4.3' version marker, which are characteristic of this malware's host reconnaissance and command-and-control exfiltration phase.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule detects potentially malicious activity where an executable with an MD5-formatted name is created in the user's temporary folder, followed by the creation of a registry key with a matching MD5-formatted name in HKEY_CURRENT_USER\SOFTWARE\ within 15 minutes. This behavior is indicative of a persistence mechanism where malware drops a payload in a temp directory and sets a run or autorun registry key to ensure its execution upon logon or startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule detects the execution of common command-line utilities (cmd.exe, mshta.exe, AutoIt3.exe) using command-line arguments that mimic legitimate service names or security analysis tools (e.g., 'Microsoft Update Superfetch Core Endpoint Service'). This behavior is indicative of an adversary attempting to mask malicious activity by using strings that resemble benign system services or localized security scanner output, likely for obfuscation or evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the creation or modification of Windows Registry Run keys associated with the name 'SnapCart'. This behavior is characteristic of adversaries attempting to achieve persistence on a host by ensuring malicious code executes automatically upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects instances where wscript.exe spawns powershell.exe with command-line arguments indicative of stealth or obfuscation, such as hidden windows or encoded commands. This behavior is frequently associated with malicious script execution lures, such as JavaScript-based droppers or ClickFix-style campaigns that use PowerShell to stage and execute in-memory payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
101
Page 182 of 1871