Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the use of PowerShell command lines containing both 'AesManaged' for decryption and '[System.Reflection.Assembly]::Load' for reflective loading of a .NET assembly in memory. This pattern is consistent with the execution stage of malware such as LausivLoader, which stage encrypted payloads and load them directly into the process memory to evade disk-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects the creation of a scheduled task named 'MicrosoftEdgeUpdateTaskCore' that is configured to execute a malicious JavaScript file named 'PhotoStudio.js' using wscript.exe with silent flags. This behavior is indicative of persistence mechanisms employed by the LausivLoader malware family.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects the execution of PowerShell scripts that utilize a multi-stage deobfuscation and loading technique. The script decrypts a staged payload using AesManaged (with specific hardcoded byte constants), decompresses the result via GZipStream, and uses [System.Reflection.Assembly]::Load to reflectively execute the resulting .NET assembly in memory. This pattern is characteristic of advanced malware loader chains, such as those used by the 'LausivLoader'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
This rule detects a suspicious sequence of events occurring on a host within a 600-second window: the modification of the Windows Trusted Root Certificate store (via certutil or registry manipulation) followed by the writing of a new executable file. This behavior is indicative of an adversary establishing persistence or preparing to bypass security controls by installing a malicious CA certificate and dropping a packed binary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
103
Detects the 'comet.exe' process (Perplexity AI agent) performing file read, write, rename, or creation operations outside of standard browser paths (e.g., AppData, Temp, Downloads). This behavior potentially indicates the process is being leveraged for unauthorized data access or staging files on the local filesystem.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
407
Detects the use of certutil.exe to add a certificate to the root store. Adversaries may perform this action to establish persistence or facilitate interception of encrypted traffic by adding a malicious CA certificate to the trusted root store.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
207
Detects the execution of PowerShell commands that enumerate files within sensitive user directories such as Desktop, Downloads, Documents, or OneDrive, using common cmdlets like Get-ChildItem with recurrence or filtering. This behavior is indicative of an adversary attempting to discover or stage files for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
This rule detects the execution of cmd.exe or powershell.exe where the command line arguments involve the deletion or renaming of specific file names potentially associated with unauthorized activities or malware components. It looks for common command-line utilities (del, ren) being used by command shells on specific files that may indicate artifact cleanup or staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
This rule detects the use of PowerShell to download a specific payload associated with the RustyShade malware from a Backblaze B2 cloud storage bucket. It monitors command lines containing 'wget' or 'Invoke-WebRequest' targeting 'f005.backblazeb2.com' and files named 'DriverInstaller.zip'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
503
Detects the creation of hard links using 'mklink /H' targeting specific paths in ProgramData or linking to specific executable paths in AppData. This behavior is often indicative of adversaries attempting to perform file system manipulation for persistence, defense evasion, or masquerading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects malicious activity involving the HTS software update mechanism, where the legitimate updater or patch processes are leveraged to download and execute the HTSPnew.exe ransomware payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
003
Detects instances where Windows Explorer (explorer.exe) spawns cmd.exe or wscript.exe to execute batch files (.bat) or scripts with specific filenames. This behavior is often associated with malicious user activity, such as executing payloads disguised as innocuous files triggered via shell interactions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
103
This rule detects potential Quasar RAT post-infection activity by correlating the identification of keystroke logging API usage (specifically SetWindowsHookEx, GetAsyncKeyState, or GetKeyboardState) followed by an outbound network connection from the same process identifier within a ten-minute window, indicative of remote control functionality.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
103
This rule detects the use of specific tools associated with credential dumping and memory forensics, including Dokan driver installations for file system mounting, the use of DumpIt for creating memory dumps, and the subsequent analysis of these dumps using MemProcFS to access sensitive process memory information such as LSASS minidumps.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
205
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
001
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
2010
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
005
Detects high-volume outbound network scanning activity from a single compute resource, characterized by a significant number of distinct destination IP addresses and ports within a short timeframe. This behavior is indicative of automated service discovery and reconnaissance, often associated with adversary-orchestrated exploitation pipelines or botnet activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
001
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
001
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
002
This rule monitors for activity associated with specific known malicious file names (killer.exe, kill.exe) and network connections to a set of identified malicious IP addresses. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential communication or presence of these malicious artifacts.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
002
Page 187 of 1871