Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects activity related to potential browser credential theft, specifically targeting Chrome and Microsoft Edge. The rule monitors for the loading of a specific suspicious file, the presence of browser-specific decryption artifacts such as 'browser_decryption.log' or 'ProtectR3.dll', and process command-line arguments containing keywords like 'DecryptData' or 'Elevation Service' associated with browser credential extraction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
004
This rule detects the creation or modification of Windows Registry Run keys that execute rundll32.exe. This is a common persistence technique where attackers configure malicious DLLs or scripts to run automatically upon user logon or system boot by leveraging the Rundll32 utility.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
004
Detects instances where PowerShell is executed with an explorer.exe parent process, but the actual creating process differs from explorer.exe. This behavior is indicative of parent PID (PPID) spoofing, a technique often used to evade detection or masquerade the execution source by abusing the PROC_THREAD_ATTRIBUTE_PARENT_PROCESS flag in the Windows API.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
004
Detects the loading or file presence of the malicious kernel driver 'Alinubx.sys' (formerly 'CcProtect.sys'), which is utilized by attackers for Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
004
Detects the suspicious execution of ServiceModelReg.exe or command lines containing the 'Elevation:Administrator!new:' string, which is associated with bypasses of Windows User Account Control (UAC). The rule excludes trusted system processes like msiexec, TrustedInstaller, and svchost to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
004
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
105
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
104
Detects the initiation of PowerShell by the Windows Explorer process (explorer.exe), which is often indicative of malicious activity such as lateral movement or execution of scripts originating from user-triggered actions. The rule flags command lines containing obfuscated patterns, bypass arguments, or encoded commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
005
Detects when AI-powered development tools or coding assistants (such as Claude, Copilot, Gemini, or Codex) spawn suspicious child processes like command shells (cmd, powershell, bash, sh) or networking utilities (curl, wget, python). This behavior is highly atypical for integrated development environments and may indicate exploitation of the assistant's integration or malicious code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
005
This rule detects potentially unauthorized or suspicious repository interactions by monitoring 'git' commands executed by common AI-assisted coding tools or command-line developer utilities. It flags occurrences where a checkout operation occurs without accompanying standard git history or status checks, which may indicate automated exfiltration or lateral movement attempt within a developer environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
005
Detects the execution, network connections, and service installation of MeshAgent or associated binaries (e.g., mvtcs.exe). The rule identifies potential unauthorized or malicious use of this remote management software by looking for process activity, specific network connections to known infrastructure, and service persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
105
Detects the execution of ReAgentC.exe with the /disable flag, which disables the Windows Recovery Environment (WinRE). This activity is often used by adversaries to prevent system recovery or to facilitate data impact, such as ransomware deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
205
Detects the execution of PowerShell via WScript or CScript where the command line contains instructions to remove an environment variable. This pattern is commonly used by adversaries to clear sensitive environment data or bypass certain application restrictions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
103
Detects command-line activity indicating an attempt to bypass or tamper with Anti-Malware Scan Interface (AMSI) functionality. The rule flags processes invoking GetProcAddress or LoadLibrary to resolve and manipulate AMSI-specific functions like AmsiScanBuffer or AmsiScanString within amsi.dll, a common technique for disabling runtime script scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects the execution of wscript.exe with silent (/B) and no-logo (/Nologo) flags, spawned by a process named MicrosoftEdgeUpdateTaskCore. This pattern is indicative of potential living-off-the-land techniques where an adversary leverages a legitimate system task to execute scripts stealthily.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects execution of PowerShell spawned by wscript.exe or cscript.exe attempting to retrieve a process-level environment variable named 'Kv[0-9]+'. This pattern is associated with 'LausivLoader', which uses environment variables to pass file paths or malicious payloads between a legacy script host and PowerShell. The rule optionally tracks attempts to delete associated files after the handoff.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects the spawning of a hidden PowerShell process by wscript.exe via conhost.exe with the --headless argument. This pattern is characteristic of the LausivLoader malware, which utilizes obfuscated command-line arguments to execute hidden PowerShell scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects attempts to patch or disable Event Tracing for Windows (ETW) functionality by identifying memory modification operations targeting the 'EtwEventWrite' function or direct memory protection changes within 'ntdll.dll'. This is a common technique used by malware and post-exploitation tools to blind security telemetry.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects the use of .NET reflection methods such as Assembly.Load or EntryPoint.Invoke within PowerShell command lines. This behavior is frequently used by attackers to reflectively load malicious .NET assemblies or shellcode directly into process memory, bypassing disk-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects execution of PowerShell scripts spawned by wscript.exe or cscript.exe that retrieve configuration data or file paths from process-specific environment variables, a technique observed in LausivLoader to evade command-line monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects execution of PowerShell scripts spawned by wscript.exe or cscript.exe that retrieve configuration data or file paths from process-specific environment variables, a technique observed in LausivLoader to evade command-line monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Page 186 of 1871